Memberful <= 1.75.0 - Missing Authorization
medium
The Memberful plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.75.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 6.5
- Affected:
- up to 1.75.0
- Fixed in:
- 1.76.0
- Disclosed:
- Sep 22, 2025
CVE-2025-58000 on NVD →
Memberful – Membership Plugin [memberful-wp] < 1.74.0
unknown
[en] The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as si...
- Affected:
- up to 1.74.0
- Fixed in:
- 1.74.0
- Disclosed:
- Dec 17, 2024
CVE-2024-11294 on NVD →
Memberful <= 1.73.9 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
medium
The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as site me...
- CVSS:
- 5.3
- Affected:
- up to 1.73.9
- Fixed in:
- 1.74.0
- Disclosed:
- Dec 16, 2024
CVE-2024-11294 on NVD →
Memberful – Membership Plugin [memberful-wp] < 1.73.8
unknown
[en] The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up to, and including, 1.73.7 due to insufficient input sanitization and output escaping on user supplied at...
- Affected:
- up to 1.73.8
- Fixed in:
- 1.73.8
- Disclosed:
- Oct 4, 2024
CVE-2024-9242 on NVD →
Memberful – Membership Plugin <= 1.73.7 - Authenticated (contributor+) Stored Cross-Site Scripting
medium
The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up to, and including, 1.73.7 due to insufficient input sanitization and output escaping on user supplied attribu...
- CVSS:
- 6.4
- Affected:
- up to 1.73.7
- Fixed in:
- 1.73.8
- Disclosed:
- Oct 3, 2024
CVE-2024-9242 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database