


Perceptive Security
SOC/SIEM Consultancy

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, a…
Published:
1 May 2026 at 22:00:00
Alert date:
2 May 2026 at 13:00:48
Source:
nvd.nist.gov
Web Technologies
The Paid Memberships Pro plugin for WordPress versions up to 3.6.5 contains a vulnerability that allows unauthorized modification of Stripe webhook configuration. The vulnerability exists due to missing capability checks on AJAX handlers for webhook operations. Authenticated attackers with Subscriber-level access can delete, create, or rebuild Stripe webhooks, potentially disrupting payment processing, subscription renewals, cancellations, and failed payment management. This affects all payment-related functionality for WordPress sites using this plugin with Stripe integration.
Technical details
Mitigation steps:
Affected products:
Paid Memberships Pro WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4100
https://github.com/strangerstudios/paid-memberships-pro/pull/3615
https://www.wordfence.com/threat-intel/vulnerabilities/id/5b333a3d-e416-42aa-9722-5406df0a64b3?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
