WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory <= 2.9.22 - Authenticated (Subscriber+) Payment Bypass via Stripe Checkout Plan Selection

Medium 4.3 CWE-840Fixed in 2.9.23
ID
WPSEC-2026-0703
Plugin
WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory (wp-user-manager)
Affected
from 2.9 before 2.9.23
Remediation
Update to 2.9.23 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-840
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory on WPSec AttackSurface
Fix released
Published

Description

The WP User Manager plugin for WordPress is vulnerable to Payment Bypass via the Stripe account checkout in versions 2.9 up to, and including, 2.9.22. This is due to the Billing tab offering, and the wpum_stripe_checkout AJAX handler accepting, any Stripe price configured on the site instead of only the plans the user registered for, and to the Stripe webhook marking the user's stored one-time plan as paid, or recording an active subscription, without checking which price was actually paid. This makes it possible for authenticated attackers with Subscriber-level access and above, who registered through a paid Stripe registration form, to pay for a cheaper plan and have the more expensive plan they signed up for unlocked, including that plan's role and capabilities.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0