Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-14849

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Jul 31, 2026
Vendor unknown

Description

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.

References