CVE-2026-90922: Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user can exploit it. The issue affects payment completion where the plugin accepts payment-provider-reported values without verifying them against the pending payment.
What must an attacker do to obtain a paid membership?
The attacker needs to complete a payment using an arbitrary lower amount than the pending membership payment. A mismatch in either the reported amount or currency is not verified before the membership is completed.
Which plugin versions are affected?
Paid Membership Subscriptions versions before 3.0.9 are affected.