SUMO Memberships for WooCommerce [sumomemberships] < 7.8.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0.
- Affected:
- up to 7.8.0
- Fixed in:
- 7.8.0
- Disclosed:
- Oct 22, 2025
CVE-2025-62005 on NVD →
SUMO Memberships for WooCommerce [sumomemberships] <= 7.6.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.6.0.
- Affected:
- up to 7.6.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-52757 on NVD →
SUMO Memberships for WooCommerce [sumomemberships] <= 7.6.0 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships for WooCommerce: from n/a through <= 7.6.0.
- Affected:
- up to 7.6.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-60222 on NVD →
SUMO Memberships for WooCommerce < 7.8.0 - Cross-Site Request Forgery
medium
The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 7.8.0 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 7.8.0
- Fixed in:
- 7.8.0
- Disclosed:
- Oct 15, 2025
CVE-2025-62005 on NVD →
SUMO Memberships for WooCommerce < 7.8.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Deletion
medium
The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 7.8.0 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary content.
- CVSS:
- 4.3
- Affected:
- up to 7.8.0
- Fixed in:
- 7.8.0
- Disclosed:
- Aug 27, 2025
CVE-2025-52757 on NVD →
SUMO Memberships for WooCommerce <= 7.8.0 - Authenticated (Subscriber+) Privilege Escalation
high
The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 7.8.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to gain access to administrative-level user access.
- CVSS:
- 8.8
- Affected:
- up to 7.8.0
- Fixed in:
- 7.9.0
- Disclosed:
- Aug 21, 2025
CVE-2025-60222 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database