What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
Explanation of Vulnerability in Simple Terms
02Summary
Paid Memberships Pro versions up to 3.0.4 contain an authorization bypass vulnerability that allows unauthenticated attackers to modify membership data and settings. The vulnerability stems from insufficient access controls on critical administrative functions. An attacker can exploit this over the network without requiring user interaction, potentially compromising membership records and site configuration.
What an attacker can do
03Attacker Capabilities
Modify membership data, settings, and user records without authentication.
Potential impact on your site
04Site Impact
Membership records, pricing, and site settings can be altered by unauthorized parties.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated