Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-37277 Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACL… Paid Memberships Pro 3.0.5+ Fix from $2,3002024-11-01 MEDIUM 6.5 CVE-2024-1287 The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitiv… Paid Memberships Pro 1.2.6+ Fix from $1,6002024-07-30 HIGH 7.2 CVE-2024-37486 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Me… Paid Memberships Pro 3.0.6+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2023-39990 Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. Paid Memberships Pro 1.2.4+ Fix from $1,9502024-06-19 MEDIUM 5.4 CVE-2024-1407 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg… Paid Memberships Pro 3.0+ Fix from $1,6002024-06-19 HIGH 8.8 CVE-2024-32793 Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. Paid Memberships Pro 3.0+ Fix from $1,9502024-04-24 HIGH 8.8 CVE-2024-32794 Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. Paid Memberships Pro 3.0+ Fix from $1,9502024-04-24 MEDIUM 5.3 CVE-2024-0624 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg… Paid Memberships Pro after 2.12.7 Fix from $1,6002024-01-25 MEDIUM 5.3 CVE-2023-6855 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modificati… Paid Memberships Pro after 2.12.5 Fix from $1,6002024-01-11 HIGH 8.8 CVE-2023-6187EPSS 52% The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalex… Paid Memberships Pro after 2.12.3 Fix from $1,9502023-11-18 HIGH 8.8 CVE-2023-28419 Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions. Force Display Name after 1.2 Fix from $1,9502023-11-12 MEDIUM 5.4 CVE-2023-5237 The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in … Memberlite Shortcodes 1.3.9+ Fix from $1,6002023-10-31 HIGH 8.8 CVE-2023-0631EPSS 60% The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly i… Paid Memberships Pro 2.9.12+ Fix from $1,9502023-03-20 MEDIUM 5.4 CVE-2022-4830EPSS 65% The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in t… Paid Memberships Pro 2.9.9+ Fix from $1,6002023-02-13 CRITICAL 9.8 CVE-2023-23488EPSS 92% The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of … Paid Memberships Pro 2.9.8+ Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2021-25114EPSS 82% The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users… Paid Memberships Pro 2.4.5 / 2.5.11+ Fix from $2,3002022-02-07 MEDIUM 6.1 CVE-2021-24979 The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, le… Paid Memberships Pro 2.6.6+ Fix from $1,6002021-12-27 HIGH 8.8 CVE-2021-20678 SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL comman… Paid Memberships Pro 2.5.6+ Fix from $1,9502021-03-18 HIGH 7.2 CVE-2020-5579 SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL comman… Paid Memberships Pro 2.3.3+ Fix from $1,9502020-05-20 MEDIUM 6.1 CVE-2015-5532 Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to… Paid Memberships Pro 1.8.4.3+ Fix from $1,6002017-10-23 MEDIUM 5.0 CVE-2014-8801EPSS 18% Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to r… Paid Memberships Pro 1.7.15+ Fix from $1,6002014-11-28