VYPR

Simple Membership

by WordPress

Source repositories

CVEs (31)

  • CVE-2026-12093MedJun 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2024-11088MedNov 21, 2024
    risk 0.34cvss 5.3epss 0.01

    The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been…

  • CVE-2023-6882MedJan 11, 2024
    risk 0.33cvss 6.1epss 0.00

    The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2024-49682MedOct 24, 2024
    risk 0.31cvss 4.7epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affects Simple Membership: from n/a through <= 4.5.3.

  • CVE-2024-1985MedMar 13, 2024
    risk 0.31cvss 4.7epss 0.01

    The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

  • CVE-2022-0328MedFeb 28, 2022
    risk 0.31cvss 4.7epss 0.00

    The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

  • CVE-2026-25308MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9.

  • CVE-2024-22308LowJan 24, 2024
    risk 0.22cvss 3.4epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.

  • CVE-2026-15931MedAug 3, 2026
    risk 0.00cvss 6.1epss 0.00

    The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary…

  • CVE-2026-15930CriAug 3, 2026
    risk 0.00cvss 9.4epss 0.00

    The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data…

  • CVE-2026-11855HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.00

    The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject…

Page 2 of 2