Simple Membership <= 4.7.8 - Missing Authorization
medium
The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.7.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.9
- Disclosed:
- Aug 5, 2026
CVE-2026-66712 on NVD →
Simple Membership <= 4.7.7 - Unauthenticated Stored Cross-Site Scripting
high
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...
- CVSS:
- 7.2
- Affected:
- up to 4.7.7
- Fixed in:
- 4.7.8
- Disclosed:
- Jul 24, 2026
CVE-2026-15931 on NVD →
Simple Membership <= 4.7.7 - Missing Authorization
medium
The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.7.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.7.7
- Fixed in:
- 4.7.8
- Disclosed:
- Jul 24, 2026
CVE-2026-15930 on NVD →
Simple Membership <= 4.7.6 - Unauthenticated Payment Verification Bypass
medium
The Simple Membership plugin for WordPress is vulnerable to Payment Verification Bypass in versions up to, and including, 4.7.6. This is due to missing verification that the PayPal IPN receiver_email matches the configured PayPal email for the payment button. This makes it possible for unauthenticated attackers to bypa...
- CVSS:
- 5.3
- Affected:
- up to 4.7.6
- Fixed in:
- 4.7.7
- Disclosed:
- Jul 13, 2026
CVE-2026-14936 on NVD →
Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook
medium
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by f...
- CVSS:
- 5.3
- Affected:
- up to 4.7.5
- Fixed in:
- 4.7.6
- Disclosed:
- Jun 17, 2026
CVE-2026-12093 on NVD →
Simple Membership <= 4.7.2 - Unauthenticated Stored Cross-Site Scripting
high
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...
- CVSS:
- 7.2
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.3
- Disclosed:
- May 3, 2026
CVE-2026-42663 on NVD →
Simple Membership <= 4.7.1 - Missing Authorization
medium
The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.7.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Mar 31, 2026
CVE-2026-34886 on NVD →
Simple Membership [simple-membership] <= 4.6.9 (unfixed)
unknown
[en] Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9.
- Affected:
- up to 4.6.9
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25308 on NVD →
Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
medium
The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by default...
- CVSS:
- 6.5
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.1
- Disclosed:
- Feb 18, 2026
CVE-2026-1461 on NVD →
Simple Membership <= 4.6.9 - Missing Authorization
medium
The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.6.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Jan 19, 2026
CVE-2026-25308 on NVD →
Simple Membership [simple-membership] < 4.6.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership allows Stored XSS. This issue affects Simple Membership: from n/a through 4.6.3.
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.4
- Disclosed:
- Jun 6, 2025
CVE-2025-49333 on NVD →
Simple Membership <= 4.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 4.4
- Affected:
- up to 4.6.3
- Fixed in:
- 4.6.4
- Disclosed:
- Jun 5, 2025
CVE-2025-49333 on NVD →
Simple Membership [simple-membership] < 4.5.6
unknown
[en] The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles suc...
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- Nov 21, 2024
CVE-2024-11088 on NVD →
Simple Membership <= 4.5.5 - Exposure of Private Personal Information to an Unauthorized Actor
medium
The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as...
- CVSS:
- 5.3
- Affected:
- up to 4.5.5
- Fixed in:
- 4.5.6
- Disclosed:
- Nov 20, 2024
CVE-2024-11088 on NVD →
Simple Membership [simple-membership] < 4.5.4
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership allows Phishing.This issue affects Simple Membership: from n/a through 4.5.3.
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.4
- Disclosed:
- Oct 24, 2024
CVE-2024-49682 on NVD →
Simple Membership <= 4.5.3 - Unauthenticated Open Redirect
medium
The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.5.3. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.4
- Disclosed:
- Oct 21, 2024
CVE-2024-49682 on NVD →
Simple Membership [simple-membership] < 4.3.5
unknown
[en] Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.5
- Disclosed:
- May 17, 2024
CVE-2023-41956 on NVD →
Simple Membership [simple-membership] < 4.3.5
unknown
[en] Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.5
- Disclosed:
- May 17, 2024
CVE-2023-41957 on NVD →
Simple Membership [simple-membership] < 4.4.6
unknown
[en] The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.6
- Disclosed:
- May 9, 2024
CVE-2024-4383 on NVD →
Simple Membership <= 4.4.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.6
- Disclosed:
- May 3, 2024
CVE-2024-4383 on NVD →
Simple Membership [simple-membership] < 4.4.4
unknown
[en] The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- Apr 25, 2024
CVE-2024-3730 on NVD →
Simple Membership <= 4.4.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 5.4
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- Apr 24, 2024
CVE-2024-3730 on NVD →
Simple Membership [simple-membership] < 4.4.3
unknown
[en] The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Mar 13, 2024
CVE-2024-1985 on NVD →
Simple Membership <= 4.4.2 - Unauthenticated Stored Self-Based Cross-Site Scripting
medium
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 4.7
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Mar 5, 2024
CVE-2024-1985 on NVD →
Simple Membership [simple-membership] < 4.4.2
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.2
- Disclosed:
- Jan 24, 2024
CVE-2024-22308 on NVD →
Simple Membership <= 4.4.1 - Open Redirect
medium
The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.4.1. This is due to insufficient validation on the redirect url supplied via the swpm_page_url parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious site...
- CVSS:
- 6.1
- Affected:
- up to 4.4.1
- Fixed in:
- 4.4.2
- Disclosed:
- Jan 19, 2024
CVE-2024-22308 on NVD →
Simple Membership [simple-membership] < 4.3.9
unknown
[en] The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- Affected:
- up to 4.3.9
- Fixed in:
- 4.3.9
- Disclosed:
- Jan 11, 2024
CVE-2023-6882 on NVD →
Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting
medium
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to 4.3.9 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- CVSS:
- 6.1
- Affected:
- up to 4.3.9
- Fixed in:
- 4.3.9
- Disclosed:
- Dec 19, 2023
CVE-2023-50376 on NVD →
Simple Membership [simple-membership] < 4.3.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8.
- Affected:
- up to 4.3.9
- Fixed in:
- 4.3.9
- Disclosed:
- Dec 19, 2023
CVE-2023-50376 on NVD →
Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode
medium
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 4.3.8
- Fixed in:
- 4.3.9
- Disclosed:
- Dec 18, 2023
CVE-2023-6882 on NVD →
Simple Membership <= 4.3.4 - Account Takeover via Password Reset
high
The Simple Membership plugin for WordPress is vulnerable to account takeover due to missing input validation on the process_password_reset_using_link function in versions up to, and including, 4.3.4. This makes it possible for authenticated attackers to gain access to arbitrary accounts on the site via the password res...
- CVSS:
- 8.8
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.5
- Disclosed:
- Sep 25, 2023
CVE-2023-41956 on NVD →
Simple Membership <= 4.3.4 - Privilege escalation via Registration
high
The Simple Membership plugin for WordPress is vulnerable to privilege escalation due to missing input validation on the create_swpm_user function in versions up to, and including, 4.3.4. This makes it possible for unauthenticated attackers to register users with arbitrary membership levels. Since membership levels can...
- CVSS:
- 7.3
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.5
- Disclosed:
- Sep 25, 2023
CVE-2023-41957 on NVD →
Simple Membership [simple-membership] < 4.3.6
unknown
[en] The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could inject arbitrary web scripts into pa...
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.6
- Disclosed:
- Sep 6, 2023
CVE-2023-4719 on NVD →
Simple Membership <= 4.3.5 - Reflected Cross-Site Scripting
high
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could inject arbitrary web scripts into pages t...
- CVSS:
- 7.2
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.6
- Disclosed:
- Sep 5, 2023
CVE-2023-4719 on NVD →
Simple Membership [simple-membership] < 4.2.2
unknown
[en] The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such a...
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
- Disclosed:
- Jan 16, 2023
CVE-2022-4469 on NVD →
Simple Membership <= 4.2.1 - Authenticated (Contributor+) Cross Site Scripting via shortcode
medium
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Dec 21, 2022
CVE-2022-4469 on NVD →
Simple Membership [simple-membership] < 4.1.3
unknown
[en] The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Aug 1, 2022
CVE-2022-2273 on NVD →
Simple Membership [simple-membership] < 4.1.3
unknown
[en] The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Aug 1, 2022
CVE-2022-2317 on NVD →
Simple Membership <= 4.1.2 - Membership Privilege Escalation
critical
The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, and including, 4.1.2. This is due to insufficient validation on the membership level_identifier supplied which makes it possible for unauthenticated users to supplied arbitrary membership levels and be...
- CVSS:
- 9.8
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.3
- Disclosed:
- Jul 6, 2022
CVE-2022-2317 on NVD →
Simple Membership <= 4.1.2 - Membership Privilege Escalation
high
The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, and including, 4.1.2. This is due to insufficient validation on the membership membership_level supplied which makes it possible for authenticated users to supplied arbitrary membership levels and be g...
- CVSS:
- 8.8
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.3
- Disclosed:
- Jul 6, 2022
CVE-2022-2273 on NVD →
Simple Membership [simple-membership] < 4.1.1
unknown
[en] The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Jun 13, 2022
CVE-2022-1724 on NVD →
Simple Membership <= 4.1.0 - Reflected Cross-Site Scripting
medium
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- May 23, 2022
CVE-2022-1724 on NVD →
Simple Membership [simple-membership] < 4.1.0
unknown
[en] The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Mar 21, 2022
CVE-2022-0681 on NVD →
Simple Membership [simple-membership] < 4.0.9
unknown
[en] The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Feb 28, 2022
CVE-2022-0328 on NVD →
Simple Membership <= 4.0.9 - Cross-Site Request Forgery to Arbitrary Transaction Deletion
medium
The Simple Membership WordPress plugin before 4.1.0 does not have Cross-Site Request Forgery (CSRF) protections in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
- CVSS:
- 6.5
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Feb 25, 2022
CVE-2022-0681 on NVD →
Simple Membership <= 4.0.8 - Cross-Site Request Forgery to Arbitrary Member Deletion
high
The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
- CVSS:
- 8.8
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Jan 25, 2022
CVE-2022-0328 on NVD →
Simple Membership <= 4.0.3 - Authenticated (Admin+) SQL Injections
high
The Simple Membership plugin for WordPress is vulnerable to time-based SQL Injection via the 's' and 'status' parameters in versions up to, and including, 4.0.3 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentic...
- CVSS:
- 7.2
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.4
- Disclosed:
- Apr 5, 2021
Simple Membership [simple-membership] < 4.0.4
unknown
The Simple Membership plugin for WordPress is vulnerable to time-based SQL Injection via the 's' and 'status' parameters in versions up to, and including, 4.0.3 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentic...
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Apr 5, 2021
Simple Membership [simple-membership] < 3.3.3
unknown
[en] The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Aug 14, 2019
CVE-2016-10884 on NVD →
Simple Membership [simple-membership] < 3.5.7
unknown
[en] The simple-membership plugin before 3.5.7 for WordPress has XSS.
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.7
- Disclosed:
- Aug 12, 2019
CVE-2017-18499 on NVD →
Simple Membership [simple-membership] < 3.8.5
unknown
[en] The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
- Affected:
- up to 3.8.5
- Fixed in:
- 3.8.5
- Disclosed:
- Jul 28, 2019
CVE-2019-14328 on NVD →
Simple Membership <= 3.8.4 - Cross-Site Request Forgery
high
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
- CVSS:
- 8.8
- Affected:
- up to 3.8.5
- Fixed in:
- 3.8.5
- Disclosed:
- Jul 27, 2019
CVE-2019-14328 on NVD →
Simple Membership <= 3.5.6 - Cross-Site Scripting
medium
The Simple Membership plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.7
- Disclosed:
- Nov 8, 2017
CVE-2017-18499 on NVD →
Simple Membership <= 3.3.2 - Multiple Cross-Site Request Forgery
high
The Simple Membership plugin for WordPress is vulnerable to multiple Cross-Site Request Forgery attacks in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain administrative access and perform otherwise restricted actio...
- CVSS:
- 8.8
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Sep 16, 2016
CVE-2016-10884 on NVD →
Simple Membership < 3.2.9 - Reflected Cross-Site Scripting
medium
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Jul 14, 2016
Simple Membership [simple-membership] < 3.2.9
unknown
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Jul 14, 2016
Simple Membership [simple-membership] < 3.2.9
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Jul 14, 2016
Simple Membership [simple-membership] < 3.2.9
unknown
The Simple Membership WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
Simple Membership [simple-membership] < 4.0.4
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
CVE-2021-29232 on NVD →