Extension WordPress
Vulnérabilités Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions, page 2
Cette page rassemble les failles publiées pour Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
27 fiches
Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.2 – IDOR to Sensitive Information Disclosure
The Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions plugin for WordPress is vulnerable to sensitive information disclosure due to incorrect user validation and capabiltiy checking on the pmpro_get_order_json() function…
[*, 2.5.3)
2.5.3
06/01/2021
Paid Memberships Pro <= 2.5.0 – Cross-Site Scripting
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
*-2.5.0
2.5.1
16/11/2020
Paid Memberships Pro <= 2.4.2 – Cross-Site Request Forgery Bypass
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for…
[*, 2.4.3)
2.4.3
16/09/2020
Paid Memberships Pro < 2.3.3 – Authenticated SQL Injection
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. The 'discount_code_id' found in the ~/adminpages/orders.php is the specific parameter that is vulnerable.
[*, 2.3.3)
2.3.3
19/05/2020
Paid Memberships Pro <= 2.0.5 – Open Redirect
The Paid Memberships Pro plugin for WordPress is vulnerable to an open redirect vulnerability in versions up to, and including, 2.0.5. This is due to missing redirect location verification on the pmpro_redirect_to_logged_in() function. This makes it possible for…
*-2.0.5
2.0.6
01/06/2019
Paid Memberships Pro < 1.8.4.3 – Multiple Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php…
[*, 1.8.4.3)
1.8.4.3
22/07/2015
Paid Memberships Pro < 1.7.15 – Directory Traversal
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.
[*, 1.7.15)
1.7.15
14/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.