What is CVE-2026-15246?
CVE-2026-15246 is a critical vulnerability in the RealHomes Memberships WordPress plugin before version 3.1.0. Due to missing checks on payment completion, nonce validation, and user capability, any authenticated user like a Subscriber can obtain paid membership packages without paying. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-15246, RealHomes Memberships WordPress plaginində 3.1.0 versiyasından əvvəl aşkar edilmiş kritik zəiflikdir. Ödənişin tamamlandığını, nonce dəyərini və ya istifadəçi səlahiyyətini yoxlamadığı üçün, autentifikasiya olunmuş istənilən sadə 'Subscriber' istifadəçi ödənişsiz 'Paid Membership' paketləri əldə edə bilər. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-15246?
This vulnerability affects the RealHomes Memberships WordPress plugin.
What is the primary recommended mitigation for this vulnerability in the RealHomes Memberships plugin?
To protect against this vulnerability, which exists in versions prior to 3.1.0, it is recommended to update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.