MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet <= 3.2.0 - Cross-Site Request Forgery to Settings Reset
medium
The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the adminOptions() function. This makes it possible for unauthenticat...
- CVSS:
- 4.3
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.1
- Disclosed:
- Jun 27, 2025
CVE-2025-5937 on NVD →
MicroPayments <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MicroPayments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 6.4
- Affected:
- up to 2.9.29
- Fixed in:
- 2.9.30
- Disclosed:
- Mar 28, 2025
CVE-2025-31075 on NVD →
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 2.9.30
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayments allows Stored XSS. This issue affects MicroPayments: from n/a through 2.9.29.
- Affected:
- up to 2.9.30
- Fixed in:
- 2.9.30
- Disclosed:
- Mar 28, 2025
CVE-2025-31075 on NVD →
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] <= 3.1.8 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper MicroPayments allows Reflected XSS. This issue affects MicroPayments: from n/a through 3.1.6.
- Affected:
- up to 3.1.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 26, 2025
CVE-2025-26579 on NVD →
MicroPayments <= 3.2.4 - Reflected Cross-Site Scripting
medium
The MicroPayments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- Mar 12, 2025
CVE-2025-26579 on NVD →
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 2.9.30
unknown
[en] The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitization and output...
- Affected:
- up to 2.9.30
- Fixed in:
- 2.9.30
- Disclosed:
- Jan 18, 2025
CVE-2024-13391 on NVD →
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitization and output esca...
- CVSS:
- 6.4
- Affected:
- up to 2.9.29
- Fixed in:
- 2.9.30
- Disclosed:
- Jan 17, 2025
CVE-2024-13391 on NVD →
MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership <= 1.9.5 - Cross-Site Request Forgery
medium
MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership versions prior to 1.9.6 are vulnerable to Cross-site request forgery. This allows a remote unauthenticated attacker to hijack the authentication of an administrator and perform unintended operation via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Apr 20, 2022
CVE-2022-27629 on NVD →
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 1.9.6
unknown
[en] Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.6 allows a remote unauthenticated attacker to hijack the authentication of an administrator and perform unintended operation via unspecified vectors.
- Affected:
- up to 1.9.6
- Fixed in:
- 1.9.6
- Disclosed:
- Apr 20, 2022
CVE-2022-27629 on NVD →
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 3.2.1
unknown
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
CVE-2025-5937 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database