{"id":"CVE-2026-90951","title":"The Paid Membership Subscriptions  WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that mem…","summary":"The Paid Membership Subscriptions  WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that mem…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-863"],"product":"Paid Membership Subscriptions","affected":["paid_membership_subscriptions < 3.1.0"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:12:32.050","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90951","references":[{"url":"https://wpscan.com/vulnerability/bf740af6-3674-461e-83f0-22bd5c5b3378/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00154,"epssPercentile":0.03792,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T10:37:55.526356Z"},"ingestedAt":"2026-09-23T06:17:57.898Z","slug":"CVE-2026-90951","body":"## Overview\n\nThe Paid Membership Subscriptions  WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":209624,"id":"CVE-2026-90951","ts":1790162588094,"field":"cvss","old":null,"new":"3.7"},{"seq":209623,"id":"CVE-2026-90951","ts":1790162588094,"field":"severity","old":"none","new":"low"}]}