Paid Memberships Subscriptions Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Paid Membership Subscriptions plugin for WordPress, affecting all versions through 2.13.7. The issue arises in the 'pms_pb_payment_redirect_link' function, which improperly uses the 'pms_payment_id' parameter to authenticate users without adequate identity verification. This flaw allows unauthenticated attackers who know a valid payment ID to log in as any user who has made a purchase on the site.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts, potentially leading to privilege escalation if the accessed account has elevated rights.

Reproduction

To reproduce this vulnerability, an attacker must send a request to the site with a valid 'pms_payment_id' parameter. The 'pms_payment_id' value must correspond to a payment made by a user on the site. Once the request is sent, the server will authenticate the attacker as the user associated with that payment ID, bypassing normal login procedures.

Remediation

Users are advised to update the Paid Membership Subscriptions plugin to version 2.13.8, which addresses the authentication bypass issue.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
3.1
exploitability
8.6
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.