Paid Member Subscriptions Cozmoslabs Paid Member Subscriptions

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Cozmoslabs Paid Member Subscriptions.

By the Year

In 2026 there have been 4 vulnerabilities in Cozmoslabs Paid Member Subscriptions with an average score of 7.1 out of ten. Last year, in 2025 Paid Member Subscriptions had 3 security vulnerabilities published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.64.

Year Vulnerabilities Average Score
2026 4 7.08
2025 3 6.43
2024 1 7.30

It may take a day or so for new Paid Member Subscriptions vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Cozmoslabs Paid Member Subscriptions Security Vulnerabilities

IDOR in Paid Member Subscriptions Subscribers <= 3.0.7
CVE-2026-59539 7.5 - High - July 27, 2026

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

Insecure Direct Object Reference / IDOR

Unauthenticated SSRF in Paid Member Subscriptions <=3.0.4
CVE-2026-57348 7.2 - High - July 02, 2026

Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.

SSRF

Unauthenticated XSS in Paid Member Subscriptions <=2.17.3
CVE-2026-39514 7.1 - High - June 15, 2026

Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.

XSS

CVE-2025-68514: Auth Bypass via UserCtrl Key in PM Sub <=2.16.8
CVE-2025-68514 6.5 - Medium - February 20, 2026

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8.

Insecure Direct Object Reference / IDOR

Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions
CVE-2025-58600 5.3 - Medium - September 03, 2025

Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9.

AuthZ

Cozmoslabs Paid Member Subscriptions <=2.15.1 SQL Injection Vulnerability
CVE-2025-49870 7.5 - High - July 04, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows SQL Injection.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.1.

SQL Injection

Cozmoslabs Paid Member Subscriptions 2.14.3 XSS Stored
CVE-2025-31088 6.5 - Medium - March 28, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Stored XSS.This issue affects Paid Member Subscriptions: from n/a through <= 2.14.3.

XSS

Effortless Memberships Shortcode Execution Flaw
CVE-2024-10261 7.3 - High - November 09, 2024

The The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Code Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Cozmoslabs Paid Member Subscriptions or by Cozmoslabs? Click the Watch button to subscribe.

Cozmoslabs
Vendor

subscribe