Unauthenticated Server Side Request Forgery in Paid Member Subscriptions by WordPress
CVE-2026-57348

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 July 2026

What is CVE-2026-57348?

The Paid Member Subscriptions plugin for WordPress versions up to 3.0.4 is susceptible to an unauthenticated Server Side Request Forgery (SSRF) vulnerability. This flaw allows attackers to manipulate server requests, potentially leading to unauthorized access to internal resources. Websites utilizing this plugin should prioritize applying security updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Paid Member Subscriptions <= 3.0.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yangsori | Patchstack Bug Bounty Program
.