CVE-2026-6419
- EPSS 0.26%
- Veröffentlicht 23.05.2026 04:27:18
- Zuletzt bearbeitet 26.05.2026 18:55:38
The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it po...
CVE-2026-6895
- EPSS 0.25%
- Veröffentlicht 23.05.2026 04:27:17
- Zuletzt bearbeitet 26.05.2026 18:55:38
The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_s...
CVE-2026-6897
- EPSS 0.24%
- Veröffentlicht 23.05.2026 04:27:17
- Zuletzt bearbeitet 26.05.2026 18:55:38
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This ma...
CVE-2026-6898
- EPSS 0.24%
- Veröffentlicht 23.05.2026 04:27:16
- Zuletzt bearbeitet 26.05.2026 18:55:38
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possib...
CVE-2024-37109
- EPSS 0.53%
- Veröffentlicht 24.06.2024 13:15:10
- Zuletzt bearbeitet 21.11.2024 09:23:12
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.