What is CVE-2026-14847?
The CVE-2026-14847 vulnerability in Paid Membership Subscriptions WordPress plugin before version 3.0.7 allows any authenticated user with Subscriber-level access or higher to disclose other members' payment details by enumerating payment IDs, due to missing capability and nonce checks on a payment-related AJAX action.
Azərbaycanca: Paid Membership Subscriptions WordPress plugin-inin 3.0.7-dən əvvəlki versiyalarında aşkar edilən CVE-2026-14847 boşluğu, ödənişlə bağlı AJAX əməliyyatında capability və nonce yoxlamasının olmaması səbəbindən Subscriber və yuxarı səviyyəli istənilən autentifikasiya olunmuş istifadəçiyə payment ID-ləri sıralayaraq digər üzvlərin ödəniş məlumatlarını əldə etməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What level of user access is required to exploit the CVE-2026-14847 vulnerability?
Any authenticated user with Subscriber-level access or higher can exploit this vulnerability.
What is the root cause of the CVE-2026-14847 vulnerability in the Paid Membership Subscriptions plugin?
The root cause is missing capability and nonce checks on a payment-related AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.