CVE-2025-14448
- EPSS 0.01%
- Veröffentlicht 15.01.2026 05:24:19
- Zuletzt bearbeitet 24.02.2026 18:47:57
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization ...
CVE-2024-10374
- EPSS 0.19%
- Veröffentlicht 25.10.2024 12:15:02
- Zuletzt bearbeitet 31.10.2024 00:00:05
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on u...
CVE-2024-9231
- EPSS 1.91%
- Veröffentlicht 22.10.2024 10:15:07
- Zuletzt bearbeitet 30.10.2024 18:56:03
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for un...
CVE-2024-1852
- EPSS 1.55%
- Veröffentlicht 09.04.2024 19:15:20
- Zuletzt bearbeitet 06.05.2025 15:23:02
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it ...
CVE-2024-1987
- EPSS 0.15%
- Veröffentlicht 08.03.2024 06:15:52
- Zuletzt bearbeitet 12.03.2025 13:23:12
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied...
CVE-2023-6733
- EPSS 0.23%
- Veröffentlicht 04.01.2024 04:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:26
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor acce...
CVE-2023-2869
- EPSS 0.07%
- Veröffentlicht 12.07.2023 05:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:27
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated...
CVE-2019-15660
- EPSS 0.15%
- Veröffentlicht 27.08.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:13
The wp-members plugin before 3.2.8 for WordPress has CSRF.
CVE-2017-2222
- EPSS 0.28%
- Veröffentlicht 07.07.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.