What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows PHP Local File Inclusion.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.4.
Explanation of Vulnerability in Simple Terms
02Summary
Paid Member Subscriptions for WordPress contains a vulnerability that allows an attacker to read sensitive data, modify site content, or disrupt service. The attack requires network access and user interaction—typically the victim must click a malicious link or visit a compromised page. All versions up to 2.15.4 are affected. Update immediately to a version newer than 2.15.4.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, or disrupt service by tricking a user into clicking a link.
Potential impact on your site
04Site Impact
Site data and functionality at risk if users are tricked into clicking attacker-controlled links.
Conditions required to exploit
05Prerequisites
Network access and user interaction required; no authentication needed.
Key dates
06Disclosure timeline
August 20, 2025
CVE published
April 28, 2026
Record updated