CVE-2025-58600: WordPress Paid Member Subscriptions Plugin <= 2.15.9 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Member Subscriptions: from n/a through 2.15.9.
Other sources
Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58600?
CVE-2025-58600 is classified as a Missing Authorization vulnerability with potential exploitation of access control security levels.
How can I fix CVE-2025-58600?
To fix CVE-2025-58600, ensure that your access control settings for the Cozmoslabs Paid Member Subscriptions plugin are properly configured.
Which versions of the software are affected by CVE-2025-58600?
CVE-2025-58600 affects Cozmoslabs Paid Member Subscriptions versions up to and including 2.15.9.
Who is the vendor for the software associated with CVE-2025-58600?
The vendor for the affected software associated with CVE-2025-58600 is Cozmoslabs.
What type of vulnerability is CVE-2025-58600?
CVE-2025-58600 is a type of Missing Authorization vulnerability that allows exploitation of incorrectly configured access control.