CVE-2025-11835: Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.16.4 - Missing Authorization to Unauthenticated Arbitrary Member Subscription Auto Renewal
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMSAJAXCheckoutHandler::processpayment() function in all versions up to, and including, 2.16.4. This makes it possible for unauthenticated attackers to trigger stored auto-renew charges for arbitrary members.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11835?
CVE-2025-11835 is considered to have a medium severity due to the potential for unauthorized data modification.
How do I fix CVE-2025-11835?
To fix CVE-2025-11835, update the Paid Memberships Pro Memberships plugin to version 2.16.5 or later, which contains the necessary security patch.
What versions are affected by CVE-2025-11835?
Versions of the Paid Memberships Pro Memberships plugin up to and including 2.16.4 are affected by CVE-2025-11835.
What type of attack can exploit CVE-2025-11835?
CVE-2025-11835 can be exploited to perform unauthorized modifications of payment-related data within the plugin.
Is CVE-2025-11835 specific to WordPress?
Yes, CVE-2025-11835 specifically affects the Paid Memberships Pro Memberships plugin used within WordPress sites.