Vulnerability Description
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-14849?
CVE-2026-14849 is a vulnerability with a CVSS score of 3.7 (LOW). The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthentic...
How severe is CVE-2026-14849?
CVE-2026-14849 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14849?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.