CYBERHAWK / CVE / CVE-2026-4100

CVE-2026-4100

Paid Memberships Pro WordPress Plugin

HIGH CVSS 7.1 vibe

The flaw

Missing capability checks allow unauthorized Stripe webhook configuration changes.

What to do

Update to version 3.6.6 or later

▸ Scan my repo for CVE-2026-4100

References

First seen 2026-05-08 · Tracked by PickBits CyberHawk · Weekly CVE digest