A vulnerability labeled as critical has been found in properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin up to 4.16.11 on WordPress. Impacted is an unknown function. Such manipulation leads to code injection. This vulnerability is documented as CVE-2026-3309 . The attack can be executed remotely.
| Vendor | Product | Versions |
|---|---|---|
| properfraction | paid membership plugin, ecommerce, user registration form, login form, user profile & restrict content – profilepress | 0 |
Updated severity to CRITICAL, changed exploit availability to false, and added new description detailing code injection vulnerability.
Initial creation