CVE-2026-90951: Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment
Published Sep 23, 2026
·Updated
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
Affected Software
1 affected component
Cozmoslabs Paid Member Subscriptions<3.1.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit it if they possess another member's in-flight payment identifier. The issue affects the plugin's unauthenticated payment action.
2
What is the impact of successful exploitation?
The attacker can delete the targeted member's checkout state while the payment is in flight. The provided information does not indicate that payment details, accounts, or other data can be accessed.
3
Which versions are affected?
Paid Member Subscriptions versions before 3.1.0 are affected. Version 3.1.0 is identified as the fixed boundary.