plugin

Login With Yourmembership Vulnerabilities

6 known security issues reported for the Login With Yourmembership WordPress plugin. Most recent disclosed Oct 14, 2025.

3 medium

Running Login With Yourmembership on your site? Check whether your installed version is affected.

Scan your site free

Login with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes'

medium

The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to read the profile data o...

CVSS:
5.3
Affected:
up to 1.1.7
Fixed in:
1.1.8
Disclosed:
Oct 14, 2025

CVE-2025-10648 on NVD →

YourMembership Single Sign On &#8211; YM SSO Login [login-with-yourmembership] < 1.1.4

unknown

[en] Missing Authorization vulnerability in miniOrange YourMembership Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YourMembership Single Sign On: from n/a through 1.1.3.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Dec 13, 2024

CVE-2023-37987 on NVD →

YourMembership Single Sign On &#8211; YM SSO Login [login-with-yourmembership] < 1.1.4

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Login plugin <= 1.1.3 versions.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Sep 1, 2023

CVE-2023-37986 on NVD →

YourMembership Single Sign On <= 1.1.3 - Missing Authorization

medium

The YourMembership Single Sign On plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
6.5
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jul 17, 2023

CVE-2023-37987 on NVD →

YourMembership Single Sign On <= 1.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

medium

The YourMembership Single Sign On plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, t...

CVSS:
4.4
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jul 17, 2023

CVE-2023-37986 on NVD →

YourMembership Single Sign On &#8211; YM SSO Login [login-with-yourmembership] <= 1.1.7 (unfixed)

unknown
Affected:
up to 1.1.7
Fix:
No patched version reported

CVE-2025-10648 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database