plugin

Members Vulnerabilities

3 known security issues reported for the Members WordPress plugin. Most recent disclosed Jul 10, 2026.

2 medium

Running Members on your site? Check whether your installed version is affected.

Scan your site free

Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel

medium

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of...

CVSS:
5.3
Affected:
up to 3.2.22
Fixed in:
3.2.23
Disclosed:
Jul 10, 2026

CVE-2026-12426 on NVD →

Members &#8211; Membership &amp; User Role Editor Plugin [members] < 3.2.11

unknown

[en] The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restri...

Affected:
up to 3.2.11
Fixed in:
3.2.11
Disclosed:
Dec 11, 2024

CVE-2024-11008 on NVD →

Members <= 3.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted...

CVSS:
5.3
Affected:
up to 3.2.10
Fixed in:
3.2.11
Disclosed:
Dec 10, 2024

CVE-2024-11008 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database