PoC Index

CVE-2026-19709

MEDIUM 5.3EPSS 0.3%

The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.26% chance of exploitation in the next 30 days, 17th percentile
Published
2026-08-19

Proof-of-concept exploits (1)

References

Related