# WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory <= 2.9.22 - Authenticated (Subscriber+) Payment Bypass via Stripe Checkout Plan Selection

- **ID:** WPSEC-2026-0703
- **Plugin:** WP User Manager – Registration Form, Login Form, User Profile Builder & Member Directory (`wp-user-manager`), https://wordpress.org/plugins/wp-user-manager/
- **Affected versions:** from 2.9 before 2.9.23
- **Fixed in:** 2.9.23 (Update to 2.9.23 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-840
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-user-manager
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0703/

## Description

The WP User Manager plugin for WordPress is vulnerable to Payment Bypass via the Stripe account checkout in versions 2.9 up to, and including, 2.9.22. This is due to the Billing tab offering, and the wpum_stripe_checkout AJAX handler accepting, any Stripe price configured on the site instead of only the plans the user registered for, and to the Stripe webhook marking the user's stored one-time plan as paid, or recording an active subscription, without checking which price was actually paid. This makes it possible for authenticated attackers with Subscriber-level access and above, who registered through a paid Stripe registration form, to pay for a cheaper plan and have the more expensive plan they signed up for unlocked, including that plan's role and capabilities.

## References

- https://wpsec.com/vuln/WPSEC-2026-0703/
- https://plugins.svn.wordpress.org/wp-user-manager/tags/2.9.23/
- https://wordpress.org/plugins/wp-user-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0703/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
