Leaky Paywall [leaky-paywall] <= 4.22.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.5.
- Affected:
- up to 4.22.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-66124 on NVD →
Leaky Paywall <= 4.22.6 - Missing Authorization
medium
The Leaky Paywall plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.22.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.22.6
- Fixed in:
- 5.0
- Disclosed:
- Dec 10, 2025
CVE-2025-66124 on NVD →
Leaky Paywall <= 4.21.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Leaky Paywall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.21.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 4.21.7
- Fixed in:
- 4.21.8
- Disclosed:
- Mar 28, 2025
CVE-2025-31083 on NVD →
Leaky Paywall [leaky-paywall] < 4.21.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZEEN101 Leaky Paywall allows Stored XSS. This issue affects Leaky Paywall: from n/a through 4.21.7.
- Affected:
- up to 4.21.8
- Fixed in:
- 4.21.8
- Disclosed:
- Mar 28, 2025
CVE-2025-31083 on NVD →
Leaky Paywall [leaky-paywall] < 4.21.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Leaky Paywall Leaky Paywall allows Cross Site Request Forgery.This issue affects Leaky Paywall: from n/a through 4.21.2.
- Affected:
- up to 4.21.3
- Fixed in:
- 4.21.3
- Disclosed:
- Jan 2, 2025
CVE-2024-37540 on NVD →
Leaky Paywall <= 4.21.2 - Cross-Site Request Forgery
medium
The Leaky Paywall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.21.2. This is due to missing or incorrect nonce validation on the process_level_deleted function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request gra...
- CVSS:
- 4.3
- Affected:
- up to 4.21.2
- Fixed in:
- 4.21.3
- Disclosed:
- Jul 6, 2024
CVE-2024-37540 on NVD →
Leaky Paywall [leaky-paywall] < 4.20.9
unknown
[en] Missing Authorization vulnerability in Leaky Paywall.This issue affects Leaky Paywall: from n/a through 4.20.8.
- Affected:
- up to 4.20.9
- Fixed in:
- 4.20.9
- Disclosed:
- Apr 29, 2024
CVE-2024-33594 on NVD →
Leaky Paywall <= 4.20.8 - Missing Authorization to Price Manipulation
medium
The Leaky Paywall plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 4.20.8. This is due to the plugin allowing the price field to be user supplied. This makes it possible for unauthenticated attackers to alter the price of memberships.
- CVSS:
- 5.3
- Affected:
- up to 4.20.8
- Fixed in:
- 4.20.9
- Disclosed:
- Apr 25, 2024
CVE-2024-33594 on NVD →
Leaky Paywall [leaky-paywall] < 4.16.7
unknown
[en] The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.16.5. This affects multi-site ins...
- Affected:
- up to 4.16.7
- Fixed in:
- 4.16.7
- Disclosed:
- Oct 21, 2021
CVE-2021-39357 on NVD →
Leaky Paywall <= 4.16.5 Authenticated Stored Cross-Site Scripting
medium
The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.16.5. This affects multi-site installa...
- CVSS:
- 5.5
- Affected:
- up to 4.16.5
- Fixed in:
- 4.16.6
- Disclosed:
- Oct 18, 2021
CVE-2021-39357 on NVD →
Leaky Paywall [leaky-paywall] < 4.9.2
unknown
A PHP object injection vulnerability was found in WordPress Leaky Paywall Plugin. If there is a cookie set in the process_cookie_requests() function, then it would be unserialized which leads to a PHP object injection.
Update the plugin.
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.2
- Disclosed:
- Aug 17, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database