VYPR

Paid Memberships Pro

by Strangerstudios

Source repositories

CVEs (25)

  • CVE-2023-6855MedJan 11, 2024
    risk 0.27cvss 5.3epss 0.01

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the…

  • CVE-2024-32794MedApr 24, 2024
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

  • CVE-2024-0588MedApr 9, 2024
    risk 0.21cvss 4.3epss 0.01

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the…

  • CVE-2024-1279MedMar 11, 2024
    risk 0.21cvss 4.3epss 0.01

    The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

  • CVE-2014-8801Nov 28, 2014
    risk 0.04cvss epss 0.18

    Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

Page 2 of 2