WordPress · Paid Membership Plugin · CVE-2026-10820
**Name of the Vulnerable Software and Affected Versions**
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content versions prior to 4.16.17
**Description**
An Insecure Direct Object Reference occurs because the software fails to verify if the authenticated user performing a subscription action is the actual owner of the targeted subscription. This allows any user with Subscriber level permissions or higher to cancel active subscriptions belonging to other users.
**Recommendations**
Update Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content to version 4.16.17 or later.