CVE-2026-10782

RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass via 'ims_add_paypal_recurring_membership' AJAX Action

2026-07-31 19:49
dyingman

Strategic Overview

Status
Patched in 3.1.0
Affected PluginRealHomes Memberships
Affected Version<= 3.0.9
CVSS4.3Medium
CVECVE-2026-10782
View all RealHomes Memberships vulnerabilities

Vulnerability Overview

The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves any premium membership tier without completing a PayPal transaction, generating a falsified active payment receipt and gaining unauthorized access to restricted property listing allowances.

Technical Analysis

REMEDIATION: Update to version 3.1.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C