Junglewise Threat Intelligence

CVE-2026-39514: Cozmoslabs Paid Member Subscriptions unauthenticated XSS

CVE-2026-39514 · Severity: high · CVSS 7.1 · Published 2026-06-15

Executive brief

The Paid Member Subscriptions plugin for WordPress, which manages memberships and content restriction, contains a security flaw that allows attackers to inject malicious scripts into the website. An attacker could use this to redirect users to fraudulent sites, steal session information, or deface the website. This occurs when a victim clicks on a specially crafted link provided by the attacker.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Paid Member Subscriptions plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows unauthenticated attackers to inject arbitrary web scripts into pages that execute when a victim (typically an administrator or logged-in user) interacts with a crafted URL. This vulnerability is present in versions 2.17.3 and below. Successful exploitation can lead to session hijacking, unauthorized actions on behalf of the user, or redirection to malicious domains. The issue is resolved in version 3.0.0.

Affected products

  • Cozmoslabs Paid Member Subscriptions <= 2.17.3

Timeline

  • 2026-02-23: other: Vulnerability reported by researcher loris4py
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-04-20: patched: Version 3.0.0 released to address the vulnerability

References

Related threats