Strangerstudios

Paid Memberships Pro

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 11:16:09
  • Zuletzt bearbeitet 05.05.2026 19:15:34

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe...

  • EPSS 0.66%
  • Veröffentlicht 01.11.2024 15:15:23
  • Zuletzt bearbeitet 22.01.2025 18:03:11

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 30.07.2024 06:15:02
  • Zuletzt bearbeitet 22.08.2025 09:15:32

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 30.07.2024 06:15:01
  • Zuletzt bearbeitet 02.10.2025 01:38:23

The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.

  • EPSS 0.75%
  • Veröffentlicht 09.07.2024 09:15:03
  • Zuletzt bearbeitet 21.11.2024 09:23:55

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.

  • EPSS 0.39%
  • Veröffentlicht 19.06.2024 13:15:54
  • Zuletzt bearbeitet 24.01.2025 16:08:44

Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

  • EPSS 0.22%
  • Veröffentlicht 19.06.2024 07:15:45
  • Zuletzt bearbeitet 08.04.2026 19:20:40

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validati...

  • EPSS 0.3%
  • Veröffentlicht 02.05.2024 17:15:23
  • Zuletzt bearbeitet 08.04.2026 19:21:17

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation...

  • EPSS 0.25%
  • Veröffentlicht 24.04.2024 15:15:47
  • Zuletzt bearbeitet 28.04.2026 19:24:57

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

  • EPSS 0.24%
  • Veröffentlicht 24.04.2024 15:15:47
  • Zuletzt bearbeitet 28.04.2026 19:24:57

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.