Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simple Membership HIGH 7.5
CVE-2024-11088

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPr…

Fix: 4.5.6+
Fix from $1,950 2024-11-21
Simple Membership MEDIUM 6.1
CVE-2024-49682

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affect…

Fix: 4.5.4+
Fix from $1,600 2024-10-24
Simple Membership CRITICAL 9.8
CVE-2023-41957

Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: f…

Fix: 4.3.5+
Fix from $2,300 2024-05-17
Simple Membership HIGH 8.8
CVE-2023-41956

Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.

Fix: 4.3.5+
Fix from $1,950 2024-05-17
Simple Membership MEDIUM 5.4
CVE-2024-4383

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' short…

Fix: 4.4.6+
Fix from $1,600 2024-05-14
Simple Membership MEDIUM 5.4
CVE-2024-3730

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' short…

Fix: 4.4.4+
Fix from $1,600 2024-04-25
Simple Membership MEDIUM 6.1
CVE-2024-1985

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and i…

Fix: 4.4.3+
Fix from $1,600 2024-03-13
Simple Membership MEDIUM 6.1
CVE-2024-22308

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/…

Fix: 4.4.2+
Fix from $1,600 2024-01-24
Simple Membership MEDIUM 6.1
CVE-2023-6882

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to…

Fix: after 4.3.8
Fix from $1,600 2024-01-11
Simple Membership MEDIUM 6.1
CVE-2023-50376

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Refle…

Fix: after 4.3.8
Fix from $1,600 2023-12-19
Simple Membership MEDIUM 6.1
CVE-2023-4719

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and inclu…

Fix: 4.3.6+
Fix from $1,600 2023-09-06
Simple Membership MEDIUM 5.4
CVE-2022-4469

The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the …

Fix: 4.2.2+
Fix from $1,600 2023-01-16
Simple Membership CRITICAL 9.8
CVE-2022-2317

The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of …

Fix: 4.1.3+
Fix from $2,300 2022-08-01
Simple Membership HIGH 8.8
CVE-2022-2273

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing member…

Fix: 4.1.3+
Fix from $1,950 2022-08-01
Simple Membership MEDIUM 6.1
CVE-2022-1724

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, lea…

Fix: 4.1.1+
Fix from $1,600 2022-06-13
Simple Membership MEDIUM 6.5
CVE-2022-0681

The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make…

Fix: 4.1.0+
Fix from $1,600 2022-03-21
Simple Membership HIGH 8.8
CVE-2016-10884

The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.

Fix: 3.3.3+
Fix from $1,950 2019-08-14
Simple Membership MEDIUM 6.1
CVE-2017-18499

The simple-membership plugin before 3.5.7 for WordPress has XSS.

Fix: 3.5.7+
Fix from $1,600 2019-08-12
Simple Membership HIGH 8.8
CVE-2019-14328

The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

Fix: 3.8.5+
Fix from $1,950 2019-07-28