Junglewise Threat Intelligence

CVE-2026-57659: Stranger Studios Paid Memberships Pro CSRF in Add Member From Admin

CVE-2026-57659 · Severity: high · CVSS 8.8 · Published 2026-06-26

Executive brief

A security vulnerability exists in the 'Add Member From Admin' add-on for Paid Memberships Pro, a tool used to manage website subscriptions. This flaw allows an attacker to trick a site administrator into performing unintended actions, such as adding new members or changing account details, without their knowledge. If exploited, this could lead to unauthorized access to the membership system or the creation of fraudulent accounts.

Technical details

The Paid Memberships Pro - Add Member From Admin plugin for WordPress (versions 0.7.2 and below) is vulnerable to Cross-Site Request Forgery (CSRF). The vulnerability stems from a lack of nonce validation or insufficient security checks when processing administrative requests to add members. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into clicking a malicious link or visiting a specially crafted webpage. Successful exploitation allows the attacker to execute unauthorized administrative functions, such as creating new member accounts, under the context of the victim's session. The issue is resolved in version 0.7.3.

Affected products

  • Stranger Studios Paid Memberships Pro - Add Member From Admin <= 0.7.2

Timeline

  • 2026-05-12: other: Vulnerability reported by researcher Roll
  • 2026-06-26: advisory: Advisory published by Patchstack
  • 2026-06-26: patched: Version 0.7.3 released to address the issue

References