CVE-2026-19709Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-19: 3Technical Details · 2026-08-19: 208-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-19709 Membership For WooCommerce https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19709

    Post summary

    The post merely lists the CVE, the affected WooCommerce plugin, and a link to an external summary—no detailed vulnerability, exploitation, or mitigation information is provided.

    00000116
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19709 The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the on… https://www.cve.org/CVERecord?id=CVE-2026-19709 ----- Traducción: CVE-2026-19709 El … https://infoflow.cloud`

    Post summary

    The tweet announces a new vulnerability (CVE-2026-19709) in the WooCommerce Membership plugin, describing a missing secret check before comparison.

    0000038
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19709 The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the on… https://www.cve.org/CVERecord?id=CVE-2026-19709

    Post summary

    The tweet announces a missing security check in the Membership For WooCommerce WordPress plugin (CVE‑2026‑19709) but does not provide a PoC, exploit, or patch info.

    000001.0K
    58.0K followersView on X

Explore more