Subscriptions & Memberships for PayPal <= 1.1.7 - Missing Authorization
medium
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.8
- Disclosed:
- Nov 28, 2025
CVE-2025-66107 on NVD →
Subscriptions & Memberships for PayPal [subscriptions-memberships-for-paypal] < 1.1.8
unknown
[en] The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entrie...
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.8
- Disclosed:
- Nov 22, 2025
CVE-2025-12752 on NVD →
Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation
medium
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries tha...
- CVSS:
- 5.3
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.8
- Disclosed:
- Nov 21, 2025
CVE-2025-12752 on NVD →
Subscriptions & Memberships for PayPal [subscriptions-memberships-for-paypal] <= 1.1.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.
- Affected:
- up to 1.1.7
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66107 on NVD →
Subscriptions & Memberships for PayPal [subscriptions-memberships-for-paypal] < 1.1.7
unknown
[en] The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged re...
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Feb 26, 2025
CVE-2024-13560 on NVD →
Subscriptions & Memberships for PayPal <= 1.1.6 - Cross-Site Request Forgery to Arbitrary Post Deletion
medium
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Feb 25, 2025
CVE-2024-13560 on NVD →
Subscriptions & Memberships for PayPal <= 1.1.5 - Reflected Cross-Site Scripting
medium
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- CVSS:
- 6.1
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- May 25, 2022
Subscriptions & Memberships for PayPal [subscriptions-memberships-for-paypal] < 1.1.6
unknown
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- May 25, 2022
Subscriptions & Memberships for PayPal [subscriptions-memberships-for-paypal] < 1.1.3
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Subscriptions & Memberships for PayPal plugin (versions <= 1.1.2).
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.3
- Disclosed:
- Oct 11, 2021
Subscriptions & Memberships for PayPal [subscriptions-memberships-for-paypal] < 1.1.3
unknown
The plugins do not escape a page parameter before outputting it back in an attribute in various admin pages, leading to Reflected Cross-Site Scripting issues.
The issues were reported to the vendor on August 10th, 2021
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database