---
id: CVE-2026-90922
title: >-
  The Paid Membership Subscriptions  WordPress plugin before 3.0.9 does not
  verify that the amount and currency reported by the payment provider match the
  pending payment before completing it, allowing unauthenticated users to obtain
  a pai…
summary: >-
  The Paid Membership Subscriptions  WordPress plugin before 3.0.9 does not
  verify that the amount and currency reported by the payment provider match the
  pending payment before completing it, allowing unauthenticated users to obtain
  a pai…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-284
product: Paid Membership Subscriptions
affected:
  - paid_membership_subscriptions < 3.0.9
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90922'
references:
  - url: 'https://wpscan.com/vulnerability/a7f3882a-81d7-4915-b83c-10480eba493a/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00304
epssPercentile: 0.20612
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:12:03.010286Z'
ingestedAt: '2026-09-17T06:12:17.971Z'
---

## Overview

The Paid Membership Subscriptions  WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
