Access Control Flaw in Cozmoslabs Product Affects Subscription Management
CVE-2025-58600
5.3MEDIUM
What is CVE-2025-58600?
A missing authorization vulnerability exists in Cozmoslabs' Paid Member Subscriptions, which can be exploited due to incorrectly configured access control security levels. This flaw allows unauthorized users to gain access to resources or data that should be protected, particularly affecting versions from n/a through 2.15.9. Proper access control mechanisms must be implemented to safeguard sensitive subscription details and user data.
Affected Version(s)
Paid Member Subscriptions <= 2.15.9