The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.
CVE-2026-19709
NONE
EPSS 0.16%
Updated Aug 19, 2026
WordPress
CVE Details
CVE ID
CVE-2026-19709
Published Date
Aug 19, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.16%
Likelihood of exploitation in next 30 days
Percentile:
5.7th percentile (higher than 5.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory