PT-2026-36609 · Stranger Studios · Paid Memberships Pro – Content Restriction

Jared Reyes

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-4100

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the wp ajax pmpro stripe create webhook, wp ajax pmpro stripe delete webhook, and wp ajax pmpro stripe rebuild webhook AJAX handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete, create, or rebuild the site's Stripe webhook, disrupting all payment processing, subscription renewal synchronization, cancellation handling, and failed payment management.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4100

Affected Products

Paid Memberships Pro – Content Restriction