Executive brief
The Paid Membership Subscriptions WordPress plugin before 3.0.8 fails to properly verify subscription ownership during subscription changes. An authenticated user with basic Subscriber-level access can hijack another user's subscription, taking complete control over their subscription plan, status, and expiration date. This allows account takeover and denial of service to other members.
Technical details
The vulnerability is a broken access control issue (CWE-284) in the change-subscription checkout handler. When processing subscription modifications via the process_checkout or change-subscription function, the plugin does not verify that the subscription being modified belongs to the authenticated user. An attacker with a valid session nonce can submit a POST request to the change-subscription endpoint with a victim's subscription ID and a target plan ID, causing the subscription row to be reassigned to the attacker's user account. The exploit works reliably when targeting free plans, as paid plan changes are blocked by payment gateway validation. Authentication is required (Subscriber-level minimum), and the vulnerability was fixed in version 3.0.8.
Affected products
- WordPress Paid Membership Subscriptions before 3.0.8
Timeline
- 2026-07-27: disclosed
- 2026-08-04: advisory
- 2026-08-04: patched: Fixed in version 3.0.8