What the vulnerability does
01Description
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.
Explanation of Vulnerability in Simple Terms
02Summary
RealHomes Memberships versions before 3.1.0 contain an integrity vulnerability allowing authenticated users to modify data they should not have access to. The flaw requires a valid user account but no special privileges. An attacker with low-level access can alter information within the affected component, though confidentiality and availability are not impacted.
What an attacker can do
03Attacker Capabilities
Modify data or settings within the membership system that they should not be able to change.
Potential impact on your site
04Site Impact
Authenticated users can alter membership data, potentially disrupting member records or site configuration.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level privileges on the site.
Key dates
06Disclosure timeline
August 6, 2026
CVE published
August 6, 2026
Record updated