CVE-2026-15302
- EPSS 0.53%
- Veröffentlicht 10.07.2026 04:31:20
- Zuletzt bearbeitet 14.07.2026 02:16:53
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CS...
CVE-2026-27060
- EPSS 0.28%
- Veröffentlicht 02.07.2026 11:14:50
- Zuletzt bearbeitet 03.08.2026 10:16:28
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium: from n/a before 7.6.
CVE-2026-7649
- EPSS 0.34%
- Veröffentlicht 02.05.2026 06:44:06
- Zuletzt bearbeitet 05.05.2026 19:19:23
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.0.60 due to insu...
CVE-2022-47425
- EPSS 0.29%
- Veröffentlicht 09.12.2025 16:41:37
- Zuletzt bearbeitet 30.01.2026 19:36:17
Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember: from n/a through 3.4.10.
CVE-2023-39994
- EPSS 0.34%
- Veröffentlicht 02.01.2025 15:15:19
- Zuletzt bearbeitet 28.04.2026 19:21:06
Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2.
CVE-2024-10681
- EPSS 0.36%
- Veröffentlicht 06.12.2024 10:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.0.51. This is due to the software allowin...
CVE-2022-47424
- EPSS 0.22%
- Veröffentlicht 19.11.2024 18:15:19
- Zuletzt bearbeitet 26.01.2026 16:05:08
Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1.
CVE-2024-7703
- EPSS 1.14%
- Veröffentlicht 17.08.2024 12:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.37 due to insufficient i...
CVE-2023-47837
- EPSS 0.39%
- Veröffentlicht 04.06.2024 10:15:12
- Zuletzt bearbeitet 29.05.2025 20:37:47
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.
CVE-2023-51356
- EPSS 0.55%
- Veröffentlicht 17.05.2024 09:15:15
- Zuletzt bearbeitet 29.05.2025 20:38:10
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.