plugin

Wp Membership Vulnerabilities

14 known security issues reported for the Wp Membership WordPress plugin. Most recent disclosed Jan 22, 2026.

1 critical 3 high 3 medium

Running Wp Membership on your site? Check whether your installed version is affected.

Scan your site free

Membership <= 1.6.4 - Authenticated (Subscriber+) Privilege Escalation

high

The WP Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

CVSS:
8.8
Affected:
up to 1.6.4
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69292 on NVD →

Membership <= 1.6.4 - Missing Authorization

medium

The Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.6.4
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69193 on NVD →

WP Membership [wp-membership] <= 1.6.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.4.

Affected:
up to 1.6.4
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69193 on NVD →

WP Membership [wp-membership] <= 1.6.4 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4.

Affected:
up to 1.6.4
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69292 on NVD →

WP Membership <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The WP Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings.

CVSS:
4.3
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Aug 14, 2025

CVE-2025-54717 on NVD →

WP Membership [wp-membership] < 1.6.4

unknown

[en] Missing Authorization vulnerability in e-plugins WP Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Membership: from n/a through 1.6.3.

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Aug 14, 2025

CVE-2025-54717 on NVD →

WP Membership [wp-membership] < 1.6.3

unknown

[en] The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server wh...

Affected:
up to 1.6.3
Fixed in:
1.6.3
Disclosed:
Nov 9, 2024

CVE-2024-10547 on NVD →

WP Membership <= 1.6.2 - Unauthenticated Arbitrary File Upload

critical

The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which m...

CVSS:
9.8
Affected:
up to 1.6.2
Fixed in:
1.6.3
Disclosed:
Nov 8, 2024

CVE-2024-10547 on NVD →

WP Membership [wp-membership] < 1.5.7

unknown

[en] The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before 1...

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Mar 27, 2023

CVE-2020-36666 on NVD →

Multiple E-plugins (Various Versions) - Authenticated (Subscriber+) Privilege Escalation

high

Multiple plugins by the vendor E-plugins are vulnerable to privilege escalation due to insufficient restriction on several functions called via AJAX actions that set a user's role based on supplied role information. This makes it possible authenticated, subscriber-level and above attackers to elevate their privileges t...

CVSS:
8.8
Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Mar 6, 2023

CVE-2020-36666 on NVD →

WP Membership [wp-membership] <= 1.2.3

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for v...

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Jan 6, 2020

CVE-2015-4039 on NVD →

WP Membership [wp-membership] < 1.2.4

unknown

[en] The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jun 3, 2015

CVE-2015-4038 on NVD →

WP Membership <= 1.2.3 - Privilege Escalation

high

The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

CVSS:
8.8
Affected:
up to 1.2.3
Fix:
No patched version reported
Disclosed:
May 21, 2015

CVE-2015-4038 on NVD →

WP Membership <= 1.2.3 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector...

CVSS:
5.4
Affected:
up to 1.2.3
Fix:
No patched version reported
Disclosed:
May 21, 2015

CVE-2015-4039 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database