{"id":"CVE-2026-14848","published":"2026-08-04T07:16:28.823","lastModified":"2026-08-04T18:16:43.717","description":"The Paid Membership Subscriptions  WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its plan, status and expiration.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/da2ae315-a534-4ae2-a8e8-61121613437b/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}