plugin

Sumomemberships Vulnerabilities

6 known security issues reported for the Sumomemberships WordPress plugin. Most recent disclosed Oct 22, 2025.

1 high 2 medium

Running Sumomemberships on your site? Check whether your installed version is affected.

Scan your site free

SUMO Memberships for WooCommerce [sumomemberships] < 7.8.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0.

Affected:
up to 7.8.0
Fixed in:
7.8.0
Disclosed:
Oct 22, 2025

CVE-2025-62005 on NVD →

SUMO Memberships for WooCommerce [sumomemberships] <= 7.6.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.6.0.

Affected:
up to 7.6.0
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-52757 on NVD →

SUMO Memberships for WooCommerce [sumomemberships] <= 7.6.0 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.6.0.

Affected:
up to 7.6.0
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-60222 on NVD →

SUMO Memberships for WooCommerce < 7.8.0 - Cross-Site Request Forgery

medium

The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 7.8.0 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick...

CVSS:
4.3
Affected:
up to 7.8.0
Fixed in:
7.8.0
Disclosed:
Oct 15, 2025

CVE-2025-62005 on NVD →

SUMO Memberships for WooCommerce < 7.8.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Deletion

medium

The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 7.8.0 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary content.

CVSS:
4.3
Affected:
up to 7.8.0
Fixed in:
7.8.0
Disclosed:
Aug 27, 2025

CVE-2025-52757 on NVD →

SUMO Memberships for WooCommerce <= 7.8.0 - Authenticated (Subscriber+) Privilege Escalation

high

The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.8.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to gain access to administrative-level user access.

CVSS:
8.8
Affected:
up to 7.8.0
Fixed in:
7.9.0
Disclosed:
Aug 21, 2025

CVE-2025-60222 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database