CVE-2026-15246

Summary

The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.

Affected Software

VendorProductVersion RangeStatus
UnknownRealHomes Memberships0 < 3.1.0affected

Weaknesses

  • CWE-345 Insufficient Verification of Data Authenticity
  • CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References