plugin

Paid Membership Vulnerabilities

10 known security issues reported for the Paid Membership WordPress plugin. Most recent disclosed Jun 27, 2025.

5 medium

Running Paid Membership on your site? Check whether your installed version is affected.

Scan your site free

MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet <= 3.2.0 - Cross-Site Request Forgery to Settings Reset

medium

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the adminOptions() function. This makes it possible for unauthenticat...

CVSS:
4.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Jun 27, 2025

CVE-2025-5937 on NVD →

MicroPayments <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MicroPayments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 2.9.29
Fixed in:
2.9.30
Disclosed:
Mar 28, 2025

CVE-2025-31075 on NVD →

MicroPayments &#8211; Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 2.9.30

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayments allows Stored XSS. This issue affects MicroPayments: from n/a through 2.9.29.

Affected:
up to 2.9.30
Fixed in:
2.9.30
Disclosed:
Mar 28, 2025

CVE-2025-31075 on NVD →

MicroPayments &#8211; Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] <= 3.1.8 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper MicroPayments allows Reflected XSS. This issue affects MicroPayments: from n/a through 3.1.6.

Affected:
up to 3.1.8
Fix:
No patched version reported
Disclosed:
Mar 26, 2025

CVE-2025-26579 on NVD →

MicroPayments <= 3.2.4 - Reflected Cross-Site Scripting

medium

The MicroPayments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Mar 12, 2025

CVE-2025-26579 on NVD →

MicroPayments &#8211; Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 2.9.30

unknown

[en] The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitization and output...

Affected:
up to 2.9.30
Fixed in:
2.9.30
Disclosed:
Jan 18, 2025

CVE-2024-13391 on NVD →

MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitization and output esca...

CVSS:
6.4
Affected:
up to 2.9.29
Fixed in:
2.9.30
Disclosed:
Jan 17, 2025

CVE-2024-13391 on NVD →

MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership <= 1.9.5 - Cross-Site Request Forgery

medium

MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership versions prior to 1.9.6 are vulnerable to Cross-site request forgery. This allows a remote unauthenticated attacker to hijack the authentication of an administrator and perform unintended operation via unspecified vectors.

CVSS:
5.4
Affected:
up to 1.9.5
Fixed in:
1.9.6
Disclosed:
Apr 20, 2022

CVE-2022-27629 on NVD →

MicroPayments &#8211; Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 1.9.6

unknown

[en] Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.6 allows a remote unauthenticated attacker to hijack the authentication of an administrator and perform unintended operation via unspecified vectors.

Affected:
up to 1.9.6
Fixed in:
1.9.6
Disclosed:
Apr 20, 2022

CVE-2022-27629 on NVD →

MicroPayments &#8211; Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet [paid-membership] < 3.2.1

unknown
Affected:
up to 3.2.1
Fixed in:
3.2.1

CVE-2025-5937 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database