๐Ÿ” CVE Alert

CVE-2026-10820

HIGH 8.1

ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR

CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
3th

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active subscriptions via an Insecure Direct Object Reference.

Vendor unknown
Product paid membership plugin, ecommerce, user registration form, login form, user profile & restrict content
Published Jun 27, 2026
Last Updated Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown paid membership plugin, ecommerce, user registration form, login form, user profile & restrict content

Be the first to know when new high vulnerabilities affecting unknown paid membership plugin, ecommerce, user registration form, login form, user profile & restrict content are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content
0 < 4.16.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/cb7ad514-e0d5-4ff3-803a-918cdc194f39/

Credits

Haitam Lazaar WPScan