SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14849

LOW · CVSS 3.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The Paid Membership Subscriptions plugin for WordPress prior to version 3.0.7 is vulnerable due to inadequate protection of member and payment export files, which are stored in a predictable location within the uploads directory. This flaw allows unauthenticated users to access and download sensitive personal information and payment data while an export artifact exists. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-14849
Severity
LOW
CVSS
3.7
EPSS
0.18%
WordPress

Original NVD Description

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.