VYPR

ARMember Premium

by WordPress

CVEs (3)

  • CVE-2026-5076CriJun 2, 2026
    risk 0.64cvss 9.8epss

    The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a…

  • CVE-2026-5073HigJun 2, 2026
    risk 0.49cvss 7.5epss

    The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby'…

  • CVE-2026-5074MedJun 2, 2026
    risk 0.42cvss 6.5epss

    The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is…