Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Members MEDIUM 5.4
CVE-2025-14448

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user…

Fix: after 3.5.4.3
Fix from $1,600 2026-01-15
Wp Members MEDIUM 5.4
CVE-2024-10374

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all v…

Fix: 3.4.9.6+
Fix from $1,600 2024-10-25
Wp Members MEDIUM 6.1
CVE-2024-9231

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropr…

Fix: 3.4.9.6+
Fix from $1,600 2024-10-22
Wp Members MEDIUM 6.1
CVE-2024-1852

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up …

Fix: 3.4.9.3+
Fix from $1,600 2024-04-09
Wp Members MEDIUM 5.4
CVE-2024-1987

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up t…

Fix: 3.4.9.2+
Fix from $1,600 2024-03-08
Wp Members MEDIUM 6.5
CVE-2023-6733

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via…

Fix: after 3.4.8
Fix from $1,600 2024-01-04
Wp Members HIGH 8.8
CVE-2019-15660

The wp-members plugin before 3.2.8 for WordPress has CSRF.

Fix: 3.2.8+
Fix from $1,950 2019-08-27
Wp Members MEDIUM 6.1
CVE-2017-2222

Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecifie…

Fix: after 3.1.7
Fix from $1,600 2017-07-07