{
 "id": "WPSEC-2026-0703",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0703/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0703/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0703/index.md",
 "title": "WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory <= 2.9.22 - Authenticated (Subscriber+) Payment Bypass via Stripe Checkout Plan Selection",
 "description": "The WP User Manager plugin for WordPress is vulnerable to Payment Bypass via the Stripe account checkout in versions 2.9 up to, and including, 2.9.22. This is due to the Billing tab offering, and the wpum_stripe_checkout AJAX handler accepting, any Stripe price configured on the site instead of only the plans the user registered for, and to the Stripe webhook marking the user's stored one-time plan as paid, or recording an active subscription, without checking which price was actually paid. This makes it possible for authenticated attackers with Subscriber-level access and above, who registered through a paid Stripe registration form, to pay for a cheaper plan and have the more expensive plan they signed up for unlocked, including that plan's role and capabilities.",
 "plugin": {
  "slug": "wp-user-manager",
  "name": "WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory",
  "full_name": "WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory",
  "wordpress_org": "https://wordpress.org/plugins/wp-user-manager/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-user-manager/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-user-manager"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-840"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.9",
    "from_inclusive": true,
    "to": "2.9.23",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.9 before 2.9.23"
  ]
 },
 "introduced_in": "2.9",
 "fixed_in": "2.9.23",
 "remediation": "Update to 2.9.23 or later.",
 "fix_released": "2026-10-08T10:05:45+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:19.781033+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0703/",
  "https://plugins.svn.wordpress.org/wp-user-manager/tags/2.9.23/",
  "https://wordpress.org/plugins/wp-user-manager/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-user-manager",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}