What is CVE-2026-14849?
The Paid Membership Subscriptions WordPress plugin before version 3.0.7 writes member and payment export files to a predictable location within the uploads directory, lacking protection. This allows unauthenticated users to download exported data, including Personally Identifiable Information (PII), while an export artifact exists. Updating to version 3.0.7 or later is strongly recommended.
Azərbaycanca: Paid Membership Subscriptions WordPress plagini (3.0.7 öncəsi versiyalar) üzvlük və ödəniş ixrac fayllarını /uploads qovluğunda proqnozlaşdırıla bilən bir yerə yazır. Bu, autentifikasiya olunmamış şəxslərə ixrac artefaktı mövcud olduğu müddətdə həssas məlumatları (PII daxil) yükləməyə imkan yaradır. Plagini 3.0.7 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What risk does CVE-2026-14849 pose to users of the Paid Membership Subscriptions plugin?
Due to this vulnerability, unauthenticated users can download membership and payment data, including sensitive Personally Identifiable Information (PII), while an export file exists.
What measure should be taken to address the CVE-2026-14849 vulnerability?
It is strongly recommended to update the Paid Membership Subscriptions plugin to version 3.0.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.