CVE-2024-37277
- EPSS 0.48%
- Veröffentlicht 01.11.2024 15:15:23
- Zuletzt bearbeitet 22.01.2025 18:03:11
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
CVE-2024-1287
- EPSS 0.89%
- Veröffentlicht 30.07.2024 06:15:02
- Zuletzt bearbeitet 22.08.2025 09:15:32
The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
CVE-2024-1286
- EPSS 0.38%
- Veröffentlicht 30.07.2024 06:15:01
- Zuletzt bearbeitet 02.10.2025 01:38:23
The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.
CVE-2024-37486
- EPSS 0.43%
- Veröffentlicht 09.07.2024 09:15:03
- Zuletzt bearbeitet 21.11.2024 09:23:55
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
CVE-2023-39990
- EPSS 0.22%
- Veröffentlicht 19.06.2024 13:15:54
- Zuletzt bearbeitet 24.01.2025 16:08:44
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
CVE-2024-1407
- EPSS 0.2%
- Veröffentlicht 19.06.2024 07:15:45
- Zuletzt bearbeitet 17.01.2025 15:05:23
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validati...
CVE-2024-3215
- EPSS 0.19%
- Veröffentlicht 02.05.2024 17:15:23
- Zuletzt bearbeitet 17.01.2025 15:03:21
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation...
CVE-2024-32794
- EPSS 0.08%
- Veröffentlicht 24.04.2024 15:15:47
- Zuletzt bearbeitet 21.01.2025 14:49:53
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
CVE-2024-32793
- EPSS 0.1%
- Veröffentlicht 24.04.2024 15:15:47
- Zuletzt bearbeitet 22.01.2025 20:20:20
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
CVE-2024-0588
- EPSS 9.32%
- Veröffentlicht 09.04.2024 19:15:14
- Zuletzt bearbeitet 17.01.2025 19:25:52
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmp...