Known Vulnerabilities for Paid Member Subscriptions by Cozmoslabs
Listed below are 6 of the newest known vulnerabilities associated with "Paid Member Subscriptions" by "Cozmoslabs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59539 json | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-57348 json | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-39514 json | Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-14849 json | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writ... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-14848 json | The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-14847 json | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its pa... | Not Provided | 2026-07-31 | 2026-07-31 |