WP-Members - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute vulnerability
high
Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute vulnerability
- CVSS:
- 8.5
- Affected:
- up to 3.5.5.1
- Fixed in:
- 3.5.6
- Disclosed:
- Mar 3, 2026
WP-Members Membership Plugin <= 3.5.5.1 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the [wpmem_user_membership_posts] shortcode in all versions up to, and including, 3.5.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...
- CVSS:
- 6.5
- Affected:
- up to 3.5.5.1
- Fixed in:
- 3.5.6
- Disclosed:
- Mar 3, 2026
CVE-2026-2363 on NVD →
WP-Members Membership Plugin [wp-members] < 3.5.4.4
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- Affected:
- up to 3.5.4.4
- Fixed in:
- 3.5.4.4
- Disclosed:
- Jan 15, 2026
CVE-2025-14448 on NVD →
WP-Members Membership Plugin <= 3.5.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- CVSS:
- 5.4
- Affected:
- up to 3.5.4.3
- Fixed in:
- 3.5.4.4
- Disclosed:
- Jan 14, 2026
CVE-2025-14448 on NVD →
WP-Members Membership Plugin [wp-members] < 3.5.4.5
unknown
[en] The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_files/<user_id>/) without implementing proper access controls beyond basic dir...
- Affected:
- up to 3.5.4.5
- Fixed in:
- 3.5.4.5
- Disclosed:
- Jan 7, 2026
CVE-2025-12648 on NVD →
WP-Members Membership Plugin <= 3.5.4.4 - Unauthenticated Information Exposure via Unprotected Files
medium
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_files/<user_id>/) without implementing proper access controls beyond basic director...
- CVSS:
- 5.3
- Affected:
- up to 3.5.4.4
- Fixed in:
- 3.5.4.5
- Disclosed:
- Jan 6, 2026
CVE-2025-12648 on NVD →
WP-Members <= 3.5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP-Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 3.5.4.2
- Fixed in:
- 3.5.4.3
- Disclosed:
- Sep 22, 2025
CVE-2025-57973 on NVD →
WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names
medium
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenti...
- CVSS:
- 5
- Affected:
- up to 3.5.4.2
- Fixed in:
- 3.5.4.3
- Disclosed:
- Sep 8, 2025
CVE-2025-9489 on NVD →
WP-Members <= 3.5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpmem_login_link' shortcode in all versions up to, and including, 3.5.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 3.5.4.1
- Fixed in:
- 3.5.4.2
- Disclosed:
- Jul 21, 2025
CVE-2025-7495 on NVD →
WP-Members Membership Plugin [wp-members] < 3.5.4.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chad Butler WP-Members allows Stored XSS.This issue affects WP-Members: from n/a through 3.5.4.
- Affected:
- up to 3.5.4.1
- Fixed in:
- 3.5.4.1
- Disclosed:
- Jun 20, 2025
CVE-2025-50051 on NVD →
WP-Members <= 3.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP-Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.4.1
- Disclosed:
- Jun 19, 2025
CVE-2025-50051 on NVD →
WP-Members <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_memberships Shortcode
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- CVSS:
- 6.4
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- May 16, 2025
CVE-2025-4610 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.9.6
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 3.4.9.6
- Fixed in:
- 3.4.9.6
- Disclosed:
- Oct 25, 2024
CVE-2024-10374 on NVD →
WP-Members <= 3.4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 3.4.9.5
- Fixed in:
- 3.4.9.6
- Disclosed:
- Oct 24, 2024
CVE-2024-10374 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.9.6
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 3.4.9.6
- Fixed in:
- 3.4.9.6
- Disclosed:
- Oct 22, 2024
CVE-2024-9231 on NVD →
WP-Members Membership Plugin <= 3.4.9.5 - Reflected Cross-Site Scripting
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 3.4.9.5
- Fixed in:
- 3.4.9.6
- Disclosed:
- Oct 21, 2024
CVE-2024-9231 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.9.4
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers t...
- Affected:
- up to 3.4.9.4
- Fixed in:
- 3.4.9.4
- Disclosed:
- Apr 26, 2024
CVE-2024-2920 on NVD →
WP-Members Membership Plugin <= 3.4.9.3 - Unprotected Storage of Potentially Sensitive Files
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to vie...
- CVSS:
- 5.3
- Affected:
- up to 3.4.9.3
- Fixed in:
- 3.4.9.4
- Disclosed:
- Apr 25, 2024
CVE-2024-2920 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.9.3
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- Affected:
- up to 3.4.9.3
- Fixed in:
- 3.4.9.3
- Disclosed:
- Apr 9, 2024
CVE-2024-1852 on NVD →
WP-Members Membership Plugin <= 3.4.9.2 - Unauthenticated Stored Cross-Site Scripting
high
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 7.2
- Affected:
- up to 3.4.9.2
- Fixed in:
- 3.4.9.3
- Disclosed:
- Apr 1, 2024
CVE-2024-1852 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.9.2
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers w...
- Affected:
- up to 3.4.9.2
- Fixed in:
- 3.4.9.2
- Disclosed:
- Mar 8, 2024
CVE-2024-1987 on NVD →
WP-Members Membership Plugin <= 3.4.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with c...
- CVSS:
- 6.4
- Affected:
- up to 3.4.9.1
- Fixed in:
- 3.4.9.2
- Disclosed:
- Mar 7, 2024
CVE-2024-1987 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.9
unknown
[en] The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails, pa...
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.9
- Disclosed:
- Jan 4, 2024
CVE-2023-6733 on NVD →
WP-Members Membership Plugin <= 3.4.8 - Missing Authorization to Sensitive Information Exposure
medium
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails, passwor...
- CVSS:
- 6.5
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.9
- Disclosed:
- Jan 3, 2024
CVE-2023-6733 on NVD →
WP-Members Membership Plugin [wp-members] < 3.4.8
unknown
[en] The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements...
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Jul 12, 2023
CVE-2023-2869 on NVD →
WP-Members Membership <= 3.4.7.3 - Cross-Site Request Forgery to Settings Update
medium
The WP-Members Membership for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.7.3. This is due to missing or incorrect nonce validation on the do_field_reorder function. This makes it possible for unauthenticated attackers to reorder form elements via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 3.4.7.3
- Fixed in:
- 3.4.8
- Disclosed:
- Jun 22, 2023
CVE-2023-2869 on NVD →
WP-Members Membership <= 3.4.7.3 - Missing Authorization to Settings Update
medium
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on lo...
- CVSS:
- 4.3
- Affected:
- up to 3.4.7.3
- Fixed in:
- 3.4.8
- Disclosed:
- Jun 8, 2023
CVE-2023-2869 on NVD →
WP-Members Membership Plugin [wp-members] < 3.2.8.1
unknown
[en] The wp-members plugin before 3.2.8 for WordPress has CSRF.
- Affected:
- up to 3.2.8.1
- Fixed in:
- 3.2.8.1
- Disclosed:
- Aug 27, 2019
CVE-2019-15660 on NVD →
WP-Members Membership Plugin [wp-members] < 3.2.8.1
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by m0ns7er in WordPress WP-Members plugin (versions <= 3.2.7).
- Affected:
- up to 3.2.8.1
- Fixed in:
- 3.2.8.1
- Disclosed:
- Jun 16, 2019
WP-Members <= 3.2.7 - Cross-Site Request Forgery
high
The wp-members plugin before 3.2.8.1 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8.1
- Disclosed:
- Jun 13, 2019
CVE-2019-15660 on NVD →
WP-Members Membership Plugin [wp-members] < 3.1.8
unknown
[en] Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.8
- Disclosed:
- Jul 7, 2017
CVE-2017-2222 on NVD →
WP-Members < 3.1.8 - Cross-Site Scripting
medium
The WP-Members plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.8
- Disclosed:
- Jun 13, 2017
CVE-2017-2222 on NVD →
WP-Members Membership Plugin [wp-members] < 2.8.10
unknown
This plugin is prone to a cross site scripting vulnerability in wp-login.php.
Update the plugin.
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Aug 1, 2014
WP-Members Membership Plugin [wp-members] < 2.8.10
unknown
This plugin is prone to a cross site scripting vulnerability in profile.php.
Update the plugin.
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Aug 1, 2014
WP-Members Membership Plugin <= 2.8.9 - Reflected Cross-Site Scripting
high
The WP Members plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 2.8.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.1
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Jan 7, 2014
WP-Members Membership Plugin [wp-members] < 2.8.10
unknown
The WP Members plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 2.8.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
- Disclosed:
- Jan 7, 2014
WP-Members Membership Plugin [wp-members] < 2.8.10
unknown
The WP-Members Membership Plugin WordPress plugin was affected by a wp-login.php register Action Multiple Parameter Reflected XSS security vulnerability.
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
WP-Members Membership Plugin [wp-members] < 2.8.10
unknown
The WP-Members Membership Plugin WordPress plugin was affected by a profile.php Multiple Parameter Stored XSS security vulnerability.
- Affected:
- up to 2.8.10
- Fixed in:
- 2.8.10
WP-Members Membership Plugin [wp-members] < 3.5.3
unknown
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
CVE-2025-4610 on NVD →
WP-Members Membership Plugin [wp-members] < 3.5.4.2
unknown
- Affected:
- up to 3.5.4.2
- Fixed in:
- 3.5.4.2
CVE-2025-7495 on NVD →