Unauthenticated Bypass Vulnerability in Paid Member Subscriptions Plugin by WordPress
CVE-2026-97249
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-97249?
An unauthenticated bypass vulnerability exists within the Paid Member Subscriptions plugin for WordPress, specifically in versions up to 3.0.9. This flaw enables attackers to gain unauthorized access, potentially leading to unauthorized actions such as viewing private content or accessing restricted areas of the website without the need for authentication. It is crucial for users of this plugin to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Paid Member Subscriptions <= 3.0.9