Cozmoslabs Paid Member Subscriptions
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Cozmoslabs Paid Member Subscriptions.
By the Year
In 2026 there have been 4 vulnerabilities in Cozmoslabs Paid Member Subscriptions with an average score of 7.1 out of ten. Last year, in 2025 Paid Member Subscriptions had 3 security vulnerabilities published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.64.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 7.08 |
| 2025 | 3 | 6.43 |
| 2024 | 1 | 7.30 |
It may take a day or so for new Paid Member Subscriptions vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cozmoslabs Paid Member Subscriptions Security Vulnerabilities
IDOR in Paid Member Subscriptions Subscribers <= 3.0.7
CVE-2026-59539
7.5 - High
- July 27, 2026
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Insecure Direct Object Reference / IDOR
Unauthenticated SSRF in Paid Member Subscriptions <=3.0.4
CVE-2026-57348
7.2 - High
- July 02, 2026
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
SSRF
Unauthenticated XSS in Paid Member Subscriptions <=2.17.3
CVE-2026-39514
7.1 - High
- June 15, 2026
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
XSS
CVE-2025-68514: Auth Bypass via UserCtrl Key in PM Sub <=2.16.8
CVE-2025-68514
6.5 - Medium
- February 20, 2026
Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8.
Insecure Direct Object Reference / IDOR
Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions
CVE-2025-58600
5.3 - Medium
- September 03, 2025
Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9.
AuthZ
Cozmoslabs Paid Member Subscriptions <=2.15.1 SQL Injection Vulnerability
CVE-2025-49870
7.5 - High
- July 04, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows SQL Injection.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.1.
SQL Injection
Cozmoslabs Paid Member Subscriptions 2.14.3 XSS Stored
CVE-2025-31088
6.5 - Medium
- March 28, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Stored XSS.This issue affects Paid Member Subscriptions: from n/a through <= 2.14.3.
XSS
Effortless Memberships Shortcode Execution Flaw
CVE-2024-10261
7.3 - High
- November 09, 2024
The The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Code Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Cozmoslabs Paid Member Subscriptions or by Cozmoslabs? Click the Watch button to subscribe.