Junglewise Threat Intelligence

CVE-2026-57348: Cozmoslabs Paid Member Subscriptions SSRF in WordPress plugin

CVE-2026-57348 · Severity: high · CVSS 7.2 · Published 2026-07-02

Executive brief

Paid Member Subscriptions is a WordPress plugin used to manage memberships and restrict content on websites. A security flaw allows unauthenticated attackers to force the website to make unauthorized requests to other internal or external servers. This could lead to the exposure of sensitive internal data or allow the site to be used as a proxy for further attacks.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Cozmoslabs Paid Member Subscriptions plugin for WordPress (versions up to and including 3.0.4). The flaw is classified as CWE-918 and stems from insufficient validation of user-supplied URLs, allowing an unauthenticated attacker to trigger outbound network requests from the vulnerable server. This can be leveraged to scan internal networks, access metadata services, or interact with other internal systems that are not otherwise reachable from the public internet. The issue is resolved in version 3.0.5.

Affected products

  • Cozmoslabs Paid Member Subscriptions <= 3.0.4

Timeline

  • 2026-05-21: disclosed: Reported by yangsori
  • 2026-07-01: advisory: Patchstack advisory published
  • 2026-07-02: patched: NVD publication and confirmation of fix in 3.0.5

References

Related threats