Extension WordPress
Vulnérabilités WP-Members Membership Plugin
Cette page rassemble les failles publiées pour WP-Members Membership Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-Members Membership Plugin
19 fiches
WP-Members Membership Plugin <= 3.5.5.1 – Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute
The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, 3.5.5.1. This is due to insufficient escaping on the user supplied…
*-3.5.5.1
3.5.6
03/03/2026
WP-Members Membership Plugin <= 3.5.4.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output…
*-3.5.4.3
3.5.4.4
14/01/2026
WP-Members Membership Plugin <= 3.5.4.4 – Unauthenticated Information Exposure via Unprotected Files
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_files//) without implementing proper access controls beyond basic directory…
*-3.5.4.4
3.5.4.5
06/01/2026
WP-Members <= 3.5.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP-Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.5.4.2
3.5.4.3
22/09/2025
WP-Members Membership Plugin <= 3.5.4.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the software allowing users to execute an action that does not properly…
*-3.5.4.2
3.5.4.3
08/09/2025
WP-Members <= 3.5.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpmem_login_link' shortcode in all versions up to, and including, 3.5.4.1 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.5.4.1
3.5.4.2
21/07/2025
WP-Members <= 3.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP-Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.5.4
3.5.4.1
19/06/2025
WP-Members <= 3.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_memberships Shortcode
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.5.2
3.5.3
16/05/2025
WP-Members <= 3.4.9.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.4.9.5
3.4.9.6
25/10/2024
WP-Members Membership Plugin <= 3.4.9.5 – Reflected Cross-Site Scripting
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for…
*-3.4.9.5
3.4.9.6
21/10/2024
WP-Members Membership Plugin <= 3.4.9.3 – Unprotected Storage of Potentially Sensitive Files
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions.…
*-3.4.9.3
3.4.9.4
25/04/2024
WP-Members Membership Plugin <= 3.4.9.2 – Unauthenticated Stored Cross-Site Scripting
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.4.9.2
3.4.9.3
01/04/2024
WP-Members Membership Plugin <= 3.4.9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-3.4.9.1
3.4.9.2
07/03/2024
WP-Members Membership Plugin <= 3.4.8 – Missing Authorization to Sensitive Information Exposure
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to…
*-3.4.8
3.4.9
03/01/2024
WP-Members Membership <= 3.4.7.3 – Cross-Site Request Forgery to Settings Update
The WP-Members Membership for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.7.3. This is due to missing or incorrect nonce validation on the do_field_reorder function. This makes it possible for unauthenticated attackers…
*-3.4.7.3
3.4.8
22/06/2023
WP-Members Membership <= 3.4.7.3 – Missing Authorization to Settings Update
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with…
*-3.4.7.3
3.4.8
08/06/2023
WP-Members <= 3.2.7 – Cross-Site Request Forgery
The wp-members plugin before 3.2.8.1 for WordPress has CSRF.
*-3.2.7
3.2.8.1
13/06/2019
WP-Members < 3.1.8 – Cross-Site Scripting
The WP-Members plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's…
[*, 3.1.8)
3.1.8
13/06/2017
WP-Members Membership Plugin <= 2.8.9 – Reflected Cross-Site Scripting
The WP Members plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 2.8.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
[*, 2.8.10)
2.8.10
07/01/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.