Cozmoslabs Paid Membership Subscriptions
cpe:2.3:a:cozmoslabs:paid_membership_subscriptions:*:*:*:*:wordpress:*:*
- <= 2.16.4
A vulnerability exists in the Paid Membership Subscriptions WordPress plugin, specifically in versions through 2.16.4. The issue arises from a missing capability and validation check in the PMS_AJAX_Checkout_Handler::process_payment() function. This flaw allows unauthenticated attackers to manipulate data by triggering stored auto-renewal charges for arbitrary members.
Exploitation of this vulnerability allows for unauthorized initiation of auto-renewal charges on behalf of any member, potentially leading to unauthorized financial transactions.
Users can update to version 2.16.5 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.