SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19709

MEDIUM · CVSS 5.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Membership For WooCommerce WordPress plugin versions prior to 3.1.2 is vulnerable due to a lack of validation for API consumer secrets, enabling unauthenticated attackers to access REST routes and potentially disclose sensitive membership plan details. This issue primarily affects WordPress sites with the API enabled but lacking generated keys. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-19709
Severity
MEDIUM
CVSS
5.3
EPSS
0.26%
WordPress

Original NVD Description

The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.