CVE-2025-69193
- EPSS 0.05%
- Veröffentlicht 22.01.2026 16:52:30
- Zuletzt bearbeitet 26.01.2026 22:15:53
Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.4.
CVE-2025-69292
- EPSS 0.05%
- Veröffentlicht 22.01.2026 16:52:30
- Zuletzt bearbeitet 26.01.2026 22:15:53
Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4.
CVE-2025-54717
- EPSS 0.05%
- Veröffentlicht 14.08.2025 18:21:45
- Zuletzt bearbeitet 15.08.2025 13:12:51
Missing Authorization vulnerability in e-plugins WP Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Membership: from n/a through 1.6.3.
CVE-2024-10547
- EPSS 7.84%
- Veröffentlicht 09.11.2024 08:15:03
- Zuletzt bearbeitet 12.11.2024 13:56:24
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated att...
CVE-2020-36666
- EPSS 0.28%
- Veröffentlicht 27.03.2023 16:15:07
- Zuletzt bearbeitet 19.02.2025 20:15:32
The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plug...
CVE-2015-4039
- EPSS 0.3%
- Veröffentlicht 06.01.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 02:30:19
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-403...