What is CVE-2026-14848?
This vulnerability exists in the Paid Membership Subscriptions WordPress plugin before version 3.0.8. It allows any authenticated user with Subscriber-level access to take over another member's subscription via the change-subscription checkout due to missing ownership verification. Updating to the latest plugin version is recommended.
Azərbaycanca: Bu boşluq Paid Membership Subscriptions WordPress plaginində 3.0.8 versiyasından əvvəl aşkarlanıb. O, autentifikasiya olunmuş istənilən Subscriber səviyyəli istifadəçiyə başqa üzvün abunəliyini ələ keçirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which plugin was CVE-2026-14848 discovered, and what is the affected version?
This vulnerability exists in the Paid Membership Subscriptions WordPress plugin before version 3.0.8.
What level of authentication does an attacker need to exploit CVE-2026-14848?
Any authenticated user with Subscriber-level access can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.