Butlerblog

Wp-members

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 15.01.2026 05:24:19
  • Zuletzt bearbeitet 24.02.2026 18:47:57

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization ...

  • EPSS 0.19%
  • Veröffentlicht 25.10.2024 12:15:02
  • Zuletzt bearbeitet 31.10.2024 00:00:05

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on u...

  • EPSS 1.91%
  • Veröffentlicht 22.10.2024 10:15:07
  • Zuletzt bearbeitet 30.10.2024 18:56:03

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for un...

  • EPSS 1.55%
  • Veröffentlicht 09.04.2024 19:15:20
  • Zuletzt bearbeitet 06.05.2025 15:23:02

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it ...

  • EPSS 0.15%
  • Veröffentlicht 08.03.2024 06:15:52
  • Zuletzt bearbeitet 12.03.2025 13:23:12

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied...

  • EPSS 0.23%
  • Veröffentlicht 04.01.2024 04:15:09
  • Zuletzt bearbeitet 21.11.2024 08:44:26

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor acce...

  • EPSS 0.07%
  • Veröffentlicht 12.07.2023 05:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:27

The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated...

  • EPSS 0.15%
  • Veröffentlicht 27.08.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:29:13

The wp-members plugin before 3.2.8 for WordPress has CSRF.

  • EPSS 0.28%
  • Veröffentlicht 07.07.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.