Extension WordPress
Vulnérabilités Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Cette page rassemble les failles publiées pour Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
27 fiches
Paid Memberships Pro <= 3.6.5 – Missing Authorization to Authenticated (Subscriber+) Stripe Webhook Deletion and Payment Processing Disruption
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and…
*-3.6.5
3.6.6
01/05/2026
Paid Memberships Pro <= 3.0.5 – Authenticated (Administrator+) SQL Injection
The Paid Memberships Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-3.0.5
3.0.6
04/07/2024
Paid Memberships Pro <= 3.0.4 – Unauthenticated Insecure Direct Object Reference to Order Status Update
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.4 via the pmpro_twocheckoutValidate function due to missing validation…
*-3.0.4
3.0.5
28/06/2024
Paid Memberships Pro <= 2.12.10 – Cross-Site Request Forgery to Membership Modification
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation…
*-2.12.10
3.0
18/06/2024
Paid Memberships Pro <= 2.12.10 – Cross-Site Request Forgery
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation…
*-2.12.10
3.0
22/04/2024
Paid Memberships Pro <= 3.0.1 – Cross-Site Request Forgery
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation…
*-3.0.1
3.0.2
15/04/2024
Paid Memberships Pro <= 2.12.10 – Cross-Site Request Forgery
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the…
*-2.12.10
3.0
25/03/2024
Paid Memberships Pro <= 2.12.8 – Authenticated (Contributor+) Information Disclosure via Shortcode
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.8. This makes it possible for authenticated attackers, with contributor-level…
*-2.12.8
2.12.9
16/02/2024
Paid Memberships Pro <= 2.12.8 – Authenticated (Contributor+) User Meta Disclosure
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.8 via the pmpro_member shortcode. This makes it possible for…
*-2.12.8
2.12.9
08/02/2024
Paid Memberships Pro <= 2.12.7 – Cross-Site Request Forgery to Level Orders Update
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation…
*-2.12.7
2.12.8
24/01/2024
Paid Memberships Pro <= 2.12.6 – Information Exposure in Debug Logs
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.6 via debug logs. This makes it possible for unauthenticated…
*-2.12.6
2.12.7
12/01/2024
Paid Memberships Pro <= 2.12.5 – Missing Authorization via API
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function…
*-2.12.5
2.12.6
21/12/2023
Paid Memberships Pro <= 2.12.3 – Authenticated (Subscriber+) Arbitrary File Upload
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with…
*-2.12.3
2.12.4
16/11/2023
Paid Memberships Pro <= 2.9.11 – Authenticated (Subscriber+) SQL Injection via Shortcodes
The Paid Memberships Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'membership' shortcode in versions up to, and including, 2.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-2.9.11
2.9.12
28/02/2023
Paid Memberships Pro <= 2.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.9.8
2.9.9
23/01/2023
Paid Memberships Pro < 2.9.8 – Unauthenticated SQL Injection
The Paid Memberships Pro plugin for WordPress is vulnerable to SQL injection in versions before 2.9.8 via the 'code' parameter in the /pmpro/v1/order REST route. This allows unauthenticated attackers to append additional SQL queries into already existing queries…
*-2.9.7
2.9.8
12/01/2023
Paid Memberships Pro <= 2.6.6 – Unauthenticated SQL Injection
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
[*, 2.6.7)
2.6.7
07/01/2022
Paid Memberships Pro <= 2.6.5 – Reflected Cross-Site Scripting
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
[*, 2.6.6)
2.6.6
23/11/2021
Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.9.1 – Cross-Site Scripting
The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the edit order page in versions up to, and including, 2.5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 2.5.10)
2.5.10
25/06/2021
Paid Memberships Pro <= 2.5.5 – Authenticated SQL Injection
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
[*, 2.5.6)
2.5.6
05/03/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.