Simple-membership-plugin

Simple Membership

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.42%
  • Veröffentlicht 06.09.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:49

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, una...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 16.01.2023 16:15:12
  • Zuletzt bearbeitet 08.04.2025 20:15:18

The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scriptin...

Exploit
  • EPSS 0.9%
  • Veröffentlicht 01.08.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:00:45

The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.

Exploit
  • EPSS 0.68%
  • Veröffentlicht 01.08.2022 13:15:10
  • Zuletzt bearbeitet 21.11.2024 07:00:39

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.

Exploit
  • EPSS 5.22%
  • Veröffentlicht 13.06.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 06:41:19

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

Exploit
  • EPSS 0.14%
  • Veröffentlicht 21.03.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 06:39:10

The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

Exploit
  • EPSS 0.11%
  • Veröffentlicht 28.02.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 06:38:23

The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

  • EPSS 0.3%
  • Veröffentlicht 14.08.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 02:44:59

The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.

  • EPSS 0.23%
  • Veröffentlicht 12.08.2019 16:15:12
  • Zuletzt bearbeitet 21.11.2024 03:20:15

The simple-membership plugin before 3.5.7 for WordPress has XSS.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 28.07.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:26:30

The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.