Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Paid Memberships Pro CRITICAL 9.8
CVE-2024-37277

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACL…

Fix: 3.0.5+
Fix from $2,300 2024-11-01
Paid Memberships Pro MEDIUM 6.5
CVE-2024-1287

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitiv…

Fix: 1.2.6+
Fix from $1,600 2024-07-30
Paid Memberships Pro HIGH 7.2
CVE-2024-37486

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Me…

Fix: 3.0.6+
Fix from $1,950 2024-07-09
Paid Memberships Pro HIGH 8.8
CVE-2023-39990

Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

Fix: 1.2.4+
Fix from $1,950 2024-06-19
Paid Memberships Pro MEDIUM 5.4
CVE-2024-1407

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg…

Fix: 3.0+
Fix from $1,600 2024-06-19
Paid Memberships Pro HIGH 8.8
CVE-2024-32793

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

Fix: 3.0+
Fix from $1,950 2024-04-24
Paid Memberships Pro HIGH 8.8
CVE-2024-32794

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

Fix: 3.0+
Fix from $1,950 2024-04-24
Paid Memberships Pro MEDIUM 5.3
CVE-2024-0624

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg…

Fix: after 2.12.7
Fix from $1,600 2024-01-25
Paid Memberships Pro MEDIUM 5.3
CVE-2023-6855

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modificati…

Fix: after 2.12.5
Fix from $1,600 2024-01-11
Paid Memberships Pro HIGH 8.8
CVE-2023-6187EPSS 52%

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalex…

Fix: after 2.12.3
Fix from $1,950 2023-11-18
Force Display Name HIGH 8.8
CVE-2023-28419

Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.

Fix: after 1.2
Fix from $1,950 2023-11-12
Memberlite Shortcodes MEDIUM 5.4
CVE-2023-5237

The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in …

Fix: 1.3.9+
Fix from $1,600 2023-10-31
Paid Memberships Pro HIGH 8.8
CVE-2023-0631EPSS 60%

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly i…

Fix: 2.9.12+
Fix from $1,950 2023-03-20
Paid Memberships Pro MEDIUM 5.4
CVE-2022-4830EPSS 65%

The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in t…

Fix: 2.9.9+
Fix from $1,600 2023-02-13
Paid Memberships Pro CRITICAL 9.8
CVE-2023-23488EPSS 92%

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of …

Fix: 2.9.8+
Fix from $2,300 2023-01-20
Paid Memberships Pro CRITICAL 9.8
CVE-2021-25114EPSS 82%

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users…

Fix: 2.4.5 / 2.5.11+
Fix from $2,300 2022-02-07
Paid Memberships Pro MEDIUM 6.1
CVE-2021-24979

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, le…

Fix: 2.6.6+
Fix from $1,600 2021-12-27
Paid Memberships Pro HIGH 8.8
CVE-2021-20678

SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL comman…

Fix: 2.5.6+
Fix from $1,950 2021-03-18
Paid Memberships Pro HIGH 7.2
CVE-2020-5579

SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL comman…

Fix: 2.3.3+
Fix from $1,950 2020-05-20
Paid Memberships Pro MEDIUM 6.1
CVE-2015-5532

Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to…

Fix: 1.8.4.3+
Fix from $1,600 2017-10-23
Paid Memberships Pro MEDIUM 5.0
CVE-2014-8801EPSS 18%

Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to r…

Fix: 1.7.15+
Fix from $1,600 2014-11-28