CVE-2025-69193
- EPSS 0.05%
- Veröffentlicht 22.01.2026 16:52:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.4.
CVE-2025-69292
- EPSS 0.06%
- Veröffentlicht 22.01.2026 16:52:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4.
CVE-2025-54717
- EPSS 0.03%
- Veröffentlicht 14.08.2025 18:21:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.3.
CVE-2024-10547
- EPSS 10.28%
- Veröffentlicht 09.11.2024 08:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated att...
CVE-2020-36666
- EPSS 0.7%
- Veröffentlicht 27.03.2023 16:15:07
- Zuletzt bearbeitet 19.02.2025 20:15:32
The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plug...
CVE-2015-4039
- EPSS 0.25%
- Veröffentlicht 06.01.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 02:30:19
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-403...