Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-37277
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACL…
Paid Memberships Pro
3.0.5+
MEDIUM 6.5
CVE-2024-1287
The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitiv…
Paid Memberships Pro
1.2.6+
HIGH 7.2
CVE-2024-37486
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Me…
Paid Memberships Pro
3.0.6+
HIGH 8.8
CVE-2023-39990
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
Paid Memberships Pro
1.2.4+
MEDIUM 5.4
CVE-2024-1407
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg…
Paid Memberships Pro
3.0+
HIGH 8.8
CVE-2024-32793
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
Paid Memberships Pro
3.0+
HIGH 8.8
CVE-2024-32794
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
Paid Memberships Pro
3.0+
MEDIUM 5.3
CVE-2024-0624
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg…
Paid Memberships Pro
after 2.12.7
MEDIUM 5.3
CVE-2023-6855
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modificati…
Paid Memberships Pro
after 2.12.5
HIGH 8.8
CVE-2023-6187EPSS 52%
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalex…
Paid Memberships Pro
after 2.12.3
HIGH 8.8
CVE-2023-28419
Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.
Force Display Name
after 1.2
MEDIUM 5.4
CVE-2023-5237
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in …
Memberlite Shortcodes
1.3.9+
HIGH 8.8
CVE-2023-0631EPSS 60%
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly i…
Paid Memberships Pro
2.9.12+
MEDIUM 5.4
CVE-2022-4830EPSS 65%
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in t…
Paid Memberships Pro
2.9.9+
CRITICAL 9.8
CVE-2023-23488EPSS 92%
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of …
Paid Memberships Pro
2.9.8+
CRITICAL 9.8
CVE-2021-25114EPSS 82%
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users…
Paid Memberships Pro
2.4.5 / 2.5.11+
MEDIUM 6.1
CVE-2021-24979
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, le…
Paid Memberships Pro
2.6.6+
HIGH 8.8
CVE-2021-20678
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL comman…
Paid Memberships Pro
2.5.6+
HIGH 7.2
CVE-2020-5579
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL comman…
Paid Memberships Pro
2.3.3+
MEDIUM 6.1
CVE-2015-5532
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to…
Paid Memberships Pro
1.8.4.3+
MEDIUM 5.0
CVE-2014-8801EPSS 18%
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to r…
Paid Memberships Pro
1.7.15+