CVE-2026-90951
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 23, 2026
Vendor
unknown
Description
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.