CVE-2026-97249: WordPress Paid Member Subscriptions plugin <= 3.0.9 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Paid Member Subscriptions Pluginto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other privileges to attempt exploitation over the network.
Which installations are affected?
Paid Member Subscriptions versions 3.0.9 and earlier are identified as affected. The available information does not state whether any particular configuration, feature, or default setup is required.
What is the likely security impact?
The supplied CVSS vector indicates low integrity impact and no stated confidentiality or availability impact. The issue is described as a bypass vulnerability, but the available data does not specify which control or membership restriction can be bypassed.