HackerFeeds
All CVEs

CVE-2026-90950

MEDIUM5.3

Published 2026-09-23 · Source contact@wpscan.com

Description

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CWE-693
View on NVD