CVE-2026-14849: Unknown Paid Membership Subscriptions
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
Affected products
- Unknown Paid Membership Subscriptions: before 3.0.7 (fixed in 3.0.7)
Published 2026-07-31. Last modified 2026-08-26.