VYPR

Paid Memberships Pro

by WordPress

CVEs (22)

  • CVE-2014-8801Nov 28, 2014
    risk 0.04cvss epss 0.18

    Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

  • CVE-2026-15016MedJul 28, 2026
    risk 0.00cvss 6.4epss 0.00

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to…

Page 2 of 2