Description
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.
INFO
Published Date :
2025-01-14T09:21:55.299Z
Last Modified :
2026-04-08T17:25:38.671Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2024-12919 vulnerability.
| Vendors | Products |
|---|---|
| Cozmoslabs |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-12919.