plugin

Paid Memberships Pro Vulnerabilities

72 known security issues reported for the Paid Memberships Pro WordPress plugin. Most recent disclosed Jul 27, 2026.

3 critical 6 high 19 medium

Running Paid Memberships Pro on your site? Check whether your installed version is affected.

Scan your site free

Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escapi...

CVSS:
6.4
Affected:
up to 3.8.1
Fixed in:
3.8.2
Disclosed:
Jul 27, 2026

CVE-2026-15016 on NVD →

Paid Memberships Pro <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Stripe Webhook Deletion and Payment Processing Disruption

high

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and `wp_ajax_...

CVSS:
7.1
Affected:
up to 3.6.5
Fixed in:
3.6.6
Disclosed:
May 1, 2026

CVE-2026-4100 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0.5 (closed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

Affected:
up to 3.0.5
Fixed in:
3.0.5
Disclosed:
Nov 1, 2024

CVE-2024-37277 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0.6 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.

Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Jul 9, 2024

CVE-2024-37486 on NVD →

Paid Memberships Pro <= 3.0.5 - Authenticated (Administrator+) SQL Injection

critical

The Paid Memberships Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level acc...

CVSS:
9.1
Affected:
up to 3.0.5
Fixed in:
3.0.6
Disclosed:
Jul 4, 2024

CVE-2024-37486 on NVD →

Paid Memberships Pro <= 3.0.4 - Unauthenticated Insecure Direct Object Reference to Order Status Update

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.4 via the pmpro_twocheckoutValidate function due to missing validation on a user controlled key. This makes it possible...

CVSS:
5.3
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Jun 28, 2024

CVE-2024-37277 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0 (closed)

unknown

[en] The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthentica...

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Jun 19, 2024

CVE-2024-1407 on NVD →

Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modification

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated a...

CVSS:
5.4
Affected:
up to 2.12.10
Fixed in:
3.0
Disclosed:
Jun 18, 2024

CVE-2024-1407 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0.2 (closed)

unknown

[en] The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it...

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
May 2, 2024

CVE-2024-3215 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Apr 24, 2024

CVE-2024-32793 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Apr 24, 2024

CVE-2024-32794 on NVD →

Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated...

CVSS:
5.4
Affected:
up to 2.12.10
Fixed in:
3.0
Disclosed:
Apr 22, 2024

CVE-2024-32793 on NVD →

Paid Memberships Pro <= 3.0.1 - Cross-Site Request Forgery

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it possi...

CVSS:
5.3
Affected:
up to 3.0.1
Fixed in:
3.0.2
Disclosed:
Apr 15, 2024

CVE-2024-3215 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 3.0 (closed)

unknown

[en] The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possib...

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Apr 9, 2024

CVE-2024-0588 on NVD →

Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible fo...

CVSS:
4.3
Affected:
up to 2.12.10
Fixed in:
3.0
Disclosed:
Mar 25, 2024

CVE-2024-0588 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.9 (closed)

unknown

[en] The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

Affected:
up to 2.12.9
Fixed in:
2.12.9
Disclosed:
Mar 11, 2024

CVE-2024-1279 on NVD →

Paid Memberships Pro <= 2.12.8 - Authenticated (Contributor+) Information Disclosure via Shortcode

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.8. This makes it possible for authenticated attackers, with contributor-level access and above, to extract user meta dat...

CVSS:
4.3
Affected:
up to 2.12.8
Fixed in:
2.12.9
Disclosed:
Feb 16, 2024

CVE-2024-1279 on NVD →

Paid Memberships Pro <= 2.12.8 - Authenticated (Contributor+) User Meta Disclosure

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.8 via the pmpro_member shortcode. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
4.3
Affected:
up to 2.12.8
Fixed in:
2.12.9
Disclosed:
Feb 8, 2024

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.9 (closed)

unknown

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.8 via the pmpro_member shortcode. This makes it possible for authenticated attackers, with contributor-level access and...

Affected:
up to 2.12.9
Fixed in:
2.12.9
Disclosed:
Feb 8, 2024

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.8 (closed)

unknown

[en] The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possi...

Affected:
up to 2.12.8
Fixed in:
2.12.8
Disclosed:
Jan 25, 2024

CVE-2024-0624 on NVD →

Paid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Update

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible f...

CVSS:
5.3
Affected:
up to 2.12.7
Fixed in:
2.12.8
Disclosed:
Jan 24, 2024

CVE-2024-0624 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.7 (closed)

unknown

Update the WordPress Paid Memberships Pro plugin to the latest available version (at least 2.12.7). WordFence discovered and reported this Sensitive Data Exposure vulnerability in WordPress Paid Memberships Pro Plugin. This vulnerability has been fixed in version 2.12.7. Have additional information or questions about...

Affected:
up to 2.12.7
Fixed in:
2.12.7
Disclosed:
Jan 15, 2024

Paid Memberships Pro <= 2.12.6 - Information Exposure in Debug Logs

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.6 via debug logs. This makes it possible for unauthenticated attackers to extract sensitive data including user password...

CVSS:
5.3
Affected:
up to 2.12.6
Fixed in:
2.12.7
Disclosed:
Jan 12, 2024

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.7 (closed)

unknown

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.6 via debug logs. This makes it possible for unauthenticated attackers to extract sensitive data including user password...

Affected:
up to 2.12.7
Fixed in:
2.12.7
Disclosed:
Jan 12, 2024

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.6 (closed)

unknown

[en] The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions...

Affected:
up to 2.12.6
Fixed in:
2.12.6
Disclosed:
Jan 11, 2024

CVE-2023-6855 on NVD →

Paid Memberships Pro <= 2.12.5 - Missing Authorization via API

medium

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to...

CVSS:
5.3
Affected:
up to 2.12.5
Fixed in:
2.12.6
Disclosed:
Dec 21, 2023

CVE-2023-6855 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.4 (closed)

unknown

[en] The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or ab...

Affected:
up to 2.12.4
Fixed in:
2.12.4
Disclosed:
Nov 18, 2023

CVE-2023-6187 on NVD →

Paid Memberships Pro <= 2.12.3 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or abo...

CVSS:
7.5
Affected:
up to 2.12.3
Fixed in:
2.12.4
Disclosed:
Nov 16, 2023

CVE-2023-6187 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.4.3 (closed)

unknown

[en] The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted...

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 20, 2023

CVE-2020-36754 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.4.3 (closed)

unknown
Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.9.12 (closed)

unknown

[en] The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

Affected:
up to 2.9.12
Fixed in:
2.9.12
Disclosed:
Mar 20, 2023

CVE-2023-0631 on NVD →

Paid Memberships Pro <= 2.9.11 - Authenticated (Subscriber+) SQL Injection via Shortcodes

high

The Paid Memberships Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'membership' shortcode in versions up to, and including, 2.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...

CVSS:
7.7
Affected:
up to 2.9.11
Fixed in:
2.9.12
Disclosed:
Feb 28, 2023

CVE-2023-0631 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.9.9 (closed)

unknown

[en] The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users suc...

Affected:
up to 2.9.9
Fixed in:
2.9.9
Disclosed:
Feb 13, 2023

CVE-2022-4830 on NVD →

Paid Memberships Pro <= 2.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor lev...

CVSS:
6.4
Affected:
up to 2.9.8
Fixed in:
2.9.9
Disclosed:
Jan 23, 2023

CVE-2022-4830 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.9.8 (closed)

unknown

[en] The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
Jan 20, 2023

CVE-2023-23488 on NVD →

Paid Memberships Pro < 2.9.8 - Unauthenticated SQL Injection

critical

The Paid Memberships Pro plugin for WordPress is vulnerable to SQL injection in versions before 2.9.8 via the 'code' parameter in the /pmpro/v1/order REST route. This allows unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from th...

CVSS:
9.8
Affected:
up to 2.9.7
Fixed in:
2.9.8
Disclosed:
Jan 12, 2023

CVE-2023-23488 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.6.7 (closed)

unknown

[en] The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

Affected:
up to 2.6.7
Fixed in:
2.6.7
Disclosed:
Feb 7, 2022

CVE-2021-25114 on NVD →

Paid Memberships Pro <= 2.6.6 - Unauthenticated SQL Injection

critical

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVSS:
9.8
Affected:
up to 2.6.7
Fixed in:
2.6.7
Disclosed:
Jan 7, 2022

CVE-2021-25114 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.6.6 (closed)

unknown

[en] The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.6.6
Fixed in:
2.6.6
Disclosed:
Dec 27, 2021

CVE-2021-24979 on NVD →

Paid Memberships Pro <= 2.6.5 - Reflected Cross-Site Scripting

medium

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.6.6
Fixed in:
2.6.6
Disclosed:
Nov 23, 2021

CVE-2021-24979 on NVD →

Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.9.1 - Cross-Site Scripting

medium

The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the edit order page in versions up to, and including, 2.5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will e...

CVSS:
6.4
Affected:
up to 2.5.10
Fixed in:
2.5.10
Disclosed:
Jun 25, 2021

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.10 (closed)

unknown

The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the edit order page in versions up to, and including, 2.5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will e...

Affected:
up to 2.5.10
Fixed in:
2.5.10
Disclosed:
Jun 25, 2021

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.6 (closed)

unknown

[en] SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Mar 18, 2021

CVE-2021-20678 on NVD →

Paid Memberships Pro <= 2.5.5 - Authenticated SQL Injection

high

SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS:
8.8
Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Mar 5, 2021

CVE-2021-20678 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.3 (closed)

unknown

Insecure Direct Object Reference & sensitive information disclosure vulnerability found in WordPress Paid Memberships Pro plugin (versions <= 2.5.2).

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Feb 6, 2021

Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.2 - IDOR to Sensitive Information Disclosure

medium

The Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions plugin for WordPress is vulnerable to sensitive information disclosure due to incorrect user validation and capabiltiy checking on the pmpro_get_order_json() function that made it possible for attackers to do...

CVSS:
4.3
Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Jan 6, 2021

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.3 (closed)

unknown

The Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions plugin for WordPress is vulnerable to sensitive information disclosure due to incorrect user validation and capabiltiy checking on the pmpro_get_order_json() function that made it possible for attackers to do...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Jan 6, 2021

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.1 (closed)

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Ron Masas from (Checkmarx) in WordPress Paid Memberships Pro plugin (versions <= 2.5).

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Dec 3, 2020

Paid Memberships Pro <= 2.5.0 - Cross-Site Scripting

medium

The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.4
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Nov 16, 2020

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.1 (closed)

unknown

The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Nov 16, 2020

Paid Memberships Pro <= 2.4.2 - Cross-Site Request Forgery Bypass

medium

The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they...

CVSS:
4.3
Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Sep 16, 2020

CVE-2020-36754 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.4.3 (closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Paid Memberships Pro plugin (versions <= 2.4.2).

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Sep 16, 2020

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.3.3 (closed)

unknown

[en] SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 20, 2020

CVE-2020-5579 on NVD →

Paid Memberships Pro < 2.3.3 - Authenticated SQL Injection

medium

SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. The 'discount_code_id' found in the ~/adminpages/orders.php is the specific parameter that is vulnerable.

CVSS:
4.7
Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 19, 2020

CVE-2020-5579 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.0.6 (closed)

unknown

Authenticated Open Redirect vulnerability found in WordPress Paid Memberships Pro plugin (versions <= 2.0.5).

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jun 11, 2019

Paid Memberships Pro <= 2.0.5 - Open Redirect

high

The Paid Memberships Pro plugin for WordPress is vulnerable to an open redirect vulnerability in versions up to, and including, 2.0.5. This is due to missing redirect location verification on the pmpro_redirect_to_logged_in() function. This makes it possible for authenticated attackers to redirect traffic to a differen...

CVSS:
7.2
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jun 1, 2019

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.0.6 (closed)

unknown

The Paid Memberships Pro plugin for WordPress is vulnerable to an open redirect vulnerability in versions up to, and including, 2.0.5. This is due to missing redirect location verification on the pmpro_redirect_to_logged_in() function. This makes it possible for authenticated attackers to redirect traffic to a differen...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jun 1, 2019

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 1.8.4.3 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter...

Affected:
up to 1.8.4.3
Fixed in:
1.8.4.3
Disclosed:
Oct 23, 2017

CVE-2015-5532 on NVD →

Paid Memberships Pro < 1.8.4.3 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to ad...

CVSS:
6.1
Affected:
up to 1.8.4.3
Fixed in:
1.8.4.3
Disclosed:
Jul 22, 2015

CVE-2015-5532 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 1.7.15 (closed)

unknown

[en] Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

Affected:
up to 1.7.15
Fixed in:
1.7.15
Disclosed:
Nov 28, 2014

CVE-2014-8801 on NVD →

Paid Memberships Pro < 1.7.15 - Directory Traversal

high

Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

CVSS:
7.5
Affected:
up to 1.7.15
Fixed in:
1.7.15
Disclosed:
Nov 14, 2014

CVE-2014-8801 on NVD →

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 1.5 (closed)

unknown

This plugin is prone to a adminpages/memberslist-csv.php direct request member personal information disclosure vulnerability. Update the plugin.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Aug 1, 2014

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.3 (closed)

unknown

The pmpro_get_order_json AJAX action, available to authenticated user did not check for authorisation, allowing any authenticated users to retrieve arbitrary order information (such as customer names, email addresses, and order numbers) via the order_id parameter.

Affected:
up to 2.5.3
Fixed in:
2.5.3

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.9 (closed)

unknown

Update the WordPress Paid Memberships Pro plugin to the latest available version (at least 2.12.9). Scott Kingsley Clark discovered and reported this Sensitive Data Exposure vulnerability in WordPress Paid Memberships Pro Plugin. This vulnerability has been fixed in version 2.12.9. Have additional information or quest...

Affected:
up to 2.12.9
Fixed in:
2.12.9

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.10 (closed)

unknown

The plugin was affected by a. Cross-Site Scripting issue in the edit order page or the admin dashboard

Affected:
up to 2.5.10
Fixed in:
2.5.10

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.5.1 (closed)

unknown

The Paid Memberships Pro WordPress plugin, versions less than 2.5.1, were affected by an Authenticated Cross-Site Scripting (XSS) vulnerability in the &#039;page &#039; paramater of the Members List page of the dashboard.

Affected:
up to 2.5.1
Fixed in:
2.5.1

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.3.3 (closed)

unknown

A high privileged user (administrator) could perform SQL injection attacks when adding new orders in the dashboard.

Affected:
up to 2.3.3
Fixed in:
2.3.3

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.12.7 (closed)

unknown

The plugin is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.12.6 via debug logs. This makes it possible for unauthenticated attackers to extract sensitive data including user passwords through debug logs.

Affected:
up to 2.12.7
Fixed in:
2.12.7

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.4.3 (closed)

unknown

NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF). The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.

Affected:
up to 2.4.3
Fixed in:
2.4.3

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.0.6 (closed)

unknown

The Paid Memberships Pro WordPress plugin was affected by an Authenticated Open Redirect security vulnerability.

Affected:
up to 2.0.6
Fixed in:
2.0.6

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 2.4.3 (closed)

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.4.3
Fixed in:
2.4.3

Paid Memberships Pro &#8211; Content Restriction, User Registration, &amp; Paid Subscriptions [paid-memberships-pro] < 1.5 (closed)

unknown

The Paid Memberships Pro WordPress plugin was affected by an adminpages/memberslist-csv.php Direct Request Member Personal Information Disclosure security vulnerability.

Affected:
up to 1.5
Fixed in:
1.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database