RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass via 'ims_add_paypal_recurring_membership' AJAX Action
medium
The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, t...
- CVSS:
- 4.3
- Affected:
- up to 3.0.9
- Fixed in:
- 3.1.0
- Disclosed:
- Jul 31, 2026
CVE-2026-10782 on NVD →
RealHomes Memberships <= 3.0.0 - Authenticated (Subscriber+) Payment Bypass
medium
The RealHomes Memberships plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 3.0.0. This is due to missing server-side verification that the membership being subscribed to is actually a free package in the free-membership handler, and missing validation of PayPal subscription and ord...
- CVSS:
- 4.3
- Affected:
- up to 3.0.0
- Fixed in:
- 3.1.0
- Disclosed:
- Jul 17, 2026
CVE-2026-15246 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database