CVE-2026-2363
- EPSS 0.03%
- Veröffentlicht 04.03.2026 06:26:52
- Zuletzt bearbeitet 04.03.2026 18:08:05
The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, 3.5.5.1. This is due to insufficient escaping on th...
CVE-2025-12648
- EPSS 0.06%
- Veröffentlicht 07.01.2026 02:21:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_files/<user_i...
- EPSS 0.06%
- Veröffentlicht 09.09.2025 04:25:55
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the software allowing users to execute an action that does not properly validate a ...
CVE-2025-7495
- EPSS 0.07%
- Veröffentlicht 22.07.2025 04:25:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpmem_login_link' shortcode in all versions up to, and including, 3.5.4.1 due to insufficient input sanitization and output escaping ...
CVE-2025-4610
- EPSS 0.23%
- Veröffentlicht 17.05.2025 09:22:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escapin...
CVE-2024-2920
- EPSS 0.39%
- Veröffentlicht 26.04.2024 08:15:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any res...