plugin

Paid Member Subscriptions Vulnerabilities

41 known security issues reported for the Paid Member Subscriptions WordPress plugin. Most recent disclosed Jul 27, 2026.

1 critical 5 high 16 medium

Running Paid Member Subscriptions on your site? Check whether your installed version is affected.

Scan your site free

Paid Member Subscriptions <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Cross-User Subscription Hijack

medium

The Paid Member Subscriptions plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.0.7. This is due to missing ownership validation on the pms_current_subscription POST parameter in the process_checkout function, allowing any authenticated user to reference subscriptions belongi...

CVSS:
4.3
Affected:
up to 3.0.7
Fixed in:
3.0.8
Disclosed:
Jul 27, 2026

CVE-2026-14848 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 3.0.7 - Insecure Direct Object Reference

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.7 due to missing validation on a user controlled key. This makes it possible for authenticated attackers,...

CVSS:
4.3
Affected:
up to 3.0.7
Fixed in:
3.0.8
Disclosed:
Jul 23, 2026

CVE-2026-59539 on NVD →

Paid Member Subscriptions <= 3.0.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Payment Data Disclosure

medium

The Paid Member Subscriptions plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.0.6. This is due to missing capability check and nonce verification on the ajax_render_modal_payment_refund function, allowing any authenticated user to query payment records by ID. T...

CVSS:
4.3
Affected:
up to 3.0.6
Fixed in:
3.0.7
Disclosed:
Jul 13, 2026

CVE-2026-14847 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 3.0.4 - Unauthenticated Server-Side Request Forgery

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.4. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating...

CVSS:
6.1
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Jul 1, 2026

CVE-2026-57348 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.17.3 - Reflected Cross-Site Scripting

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.17.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...

CVSS:
6.1
Affected:
up to 2.17.3
Fixed in:
3.0.0
Disclosed:
Apr 20, 2026

CVE-2026-39514 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] <= 2.16.8 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8.

Affected:
up to 2.16.8
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-68514 on NVD →

Paid Member Subscriptions <= 2.16.8 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.16.8 due to missing validation on a user controlled key. This makes it possible for authenticated attackers,...

CVSS:
4.3
Affected:
up to 2.16.8
Fixed in:
2.16.9
Disclosed:
Feb 11, 2026

CVE-2025-68514 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.16.5

unknown

[en] The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and inclu...

Affected:
up to 2.16.5
Fixed in:
2.16.5
Disclosed:
Nov 5, 2025

CVE-2025-11835 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.16.4 - Missing Authorization to Unauthenticated Arbitrary Member Subscription Auto Renewal

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and including,...

CVSS:
5.3
Affected:
up to 2.16.4
Fixed in:
2.16.5
Disclosed:
Nov 4, 2025

CVE-2025-11835 on NVD →

Paid Member Subscriptions <= 2.15.9 - Missing Authorization

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.15.9. This makes it possible for unauthenticated attackers to perform an...

CVSS:
5.3
Affected:
up to 2.15.9
Fixed in:
2.16.0
Disclosed:
Sep 3, 2025

CVE-2025-58600 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.16.0

unknown

[en] Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Member Subscriptions: from n/a through 2.15.9.

Affected:
up to 2.16.0
Fixed in:
2.16.0
Disclosed:
Sep 3, 2025

CVE-2025-58600 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.15.5

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions allows PHP Local File Inclusion. This issue affects Paid Member Subscriptions: from n/a through 2.15.4.

Affected:
up to 2.15.5
Fixed in:
2.15.5
Disclosed:
Aug 20, 2025

CVE-2025-54017 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.15.5

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions allows PHP Local File Inclusion. This issue affects Paid Member Subscriptions: from n/a through 2.15.4.

Affected:
up to 2.15.5
Fixed in:
2.15.5
Disclosed:
Aug 20, 2025

CVE-2025-54017 on NVD →

Paid Membership Subscriptions <= 2.15.5 - Unauthenticated Local File Inclusion

high

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.15.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowin...

CVSS:
8.1
Affected:
up to 2.15.4
Fixed in:
2.15.5
Disclosed:
Jul 29, 2025

CVE-2025-54017 on NVD →

Paid Membership Subscriptions <= 2.15.5 - Unauthenticated Local File Inclusion

high

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.15.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowin...

CVSS:
8.1
Affected:
up to 2.15.4
Fixed in:
2.15.5
Disclosed:
Jul 29, 2025

CVE-2025-54017 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.15.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL Injection. This issue affects Paid Member Subscriptions: from n/a through 2.15.1.

Affected:
up to 2.15.2
Fixed in:
2.15.2
Disclosed:
Jul 4, 2025

CVE-2025-49870 on NVD →

Paid Member Subscriptions <= 2.15.1 - Unauthenticated SQL Injection

high

The Paid Member Subscriptions plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional...

CVSS:
7.5
Affected:
up to 2.15.1
Fixed in:
2.15.2
Disclosed:
Jul 3, 2025

CVE-2025-49870 on NVD →

Paid Member Subscriptions <= 2.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Paid Member Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 2.14.3
Fixed in:
2.14.4
Disclosed:
Mar 28, 2025

CVE-2025-31088 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.14.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Paid Member Subscriptions allows Stored XSS. This issue affects Paid Member Subscriptions: from n/a through 2.14.3.

Affected:
up to 2.14.4
Fixed in:
2.14.4
Disclosed:
Mar 28, 2025

CVE-2025-31088 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.13.8

unknown

[en] The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'p...

Affected:
up to 2.13.8
Fixed in:
2.13.8
Disclosed:
Jan 14, 2025

CVE-2024-12919 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id

critical

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_pa...

CVSS:
9.8
Affected:
up to 2.13.7
Fixed in:
2.13.8
Disclosed:
Jan 13, 2025

CVE-2024-12919 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.13.5

unknown

[en] The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extra...

Affected:
up to 2.13.5
Fixed in:
2.13.5
Disclosed:
Dec 18, 2024

CVE-2024-11291 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract se...

CVSS:
5.3
Affected:
up to 2.13.4
Fixed in:
2.13.5
Disclosed:
Dec 17, 2024

CVE-2024-11291 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.13.1

unknown

[en] The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate...

Affected:
up to 2.13.1
Fixed in:
2.13.1
Disclosed:
Nov 9, 2024

CVE-2024-10261 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution

high

The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a val...

CVSS:
7.3
Affected:
up to 2.13.0
Fixed in:
2.13.1
Disclosed:
Nov 8, 2024

CVE-2024-10261 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.12.9

unknown

[en] The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for...

Affected:
up to 2.12.9
Fixed in:
2.12.9
Disclosed:
Oct 2, 2024

CVE-2024-9222 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.12.8 - Reflected Cross-Site Scripting

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for unaut...

CVSS:
6.1
Affected:
up to 2.12.8
Fixed in:
2.12.9
Disclosed:
Oct 1, 2024

CVE-2024-9222 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.11.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.11.0.

Affected:
up to 2.11.1
Fixed in:
2.11.1
Disclosed:
Apr 24, 2024

CVE-2024-32728 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.0 - Cross-Site Request Forgery to Notice Dismissal

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.0. This is due to missing or incorrect nonce validation on the dismiss_notification() function. This makes it p...

CVSS:
4.3
Affected:
up to 2.11.0
Fixed in:
2.11.1
Disclosed:
Apr 22, 2024

CVE-2024-32728 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.10.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.10.4.

Affected:
up to 2.10.5
Fixed in:
2.10.5
Disclosed:
Mar 15, 2024

CVE-2023-51522 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.11.2

unknown

[en] The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1....

Affected:
up to 2.11.2
Fixed in:
2.11.2
Disclosed:
Feb 20, 2024

CVE-2024-1389 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.11.2

unknown

[en] The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it poss...

Affected:
up to 2.11.2
Fixed in:
2.11.2
Disclosed:
Feb 20, 2024

CVE-2024-1390 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via pms_stripe_connect_handle_authorization_return

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1. This...

CVSS:
5.3
Affected:
up to 2.11.1
Fixed in:
2.11.2
Disclosed:
Feb 13, 2024

CVE-2024-1389 on NVD →

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via creating_pricing_table_page

medium

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible...

CVSS:
4.3
Affected:
up to 2.11.1
Fixed in:
2.11.2
Disclosed:
Feb 13, 2024

CVE-2024-1390 on NVD →

Paid Member Subscriptions <= 2.10.4 - Cross-Site Request Forgery via ajax_add_log_entry

medium

The Paid Member Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the ajax_add_log_entry function. This makes it possible for unauthenticated attackers to modify log entries via a forged reques...

CVSS:
4.3
Affected:
up to 2.10.4
Fixed in:
2.10.5
Disclosed:
Dec 27, 2023

CVE-2023-51522 on NVD →

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.4.2

unknown

[en] The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Sep 13, 2021

CVE-2021-24728 on NVD →

Membership & Content Restriction – Paid Member Subscriptions <= 2.4.1 - SQL Injection

high

The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to authenticated SQL injections in the Members and Payments pages.

CVSS:
8.8
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Aug 6, 2021

CVE-2021-24728 on NVD →

Paid Member Subscriptions <= 2.4.1 - Reflected Cross-Site Scripting

medium

The Paid Member Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Aug 6, 2021

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.4.2

unknown

The Paid Member Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Aug 6, 2021

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.4.2

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Paid Member Subscriptions plugin (versions <= 2.4.1).

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Jul 26, 2021

Paid Membership Subscriptions &#8211; Effortless Memberships, Recurring Payments &amp; Content Restriction [paid-member-subscriptions] < 2.4.2

unknown

The plugin was vulnerable to a Reflected Cross-Site Scripting (XSS) on the edit member page. No CSRF nonce was required.

Affected:
up to 2.4.2
Fixed in:
2.4.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database