plugin

Wpcom Member Vulnerabilities

15 known security issues reported for the Wpcom Member WordPress plugin. Most recent disclosed Dec 16, 2025.

3 critical 4 high 1 medium

Running Wpcom Member on your site? Check whether your installed version is affected.

Scan your site free

WPCOM Member [wpcom-member] < 1.7.17

unknown

[en] The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1.7.16. This is due to weak OTP (One-Time Password) generation using only 6 numeric digits combined with a 10-minute validity window and no rate limiting on verification attempts. This...

Affected:
up to 1.7.17
Fixed in:
1.7.17
Disclosed:
Dec 16, 2025

CVE-2025-14002 on NVD →

WPCOM Member <= 1.7.16 - Authentication Bypass via Weak OTP

high

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1.7.16. This is due to weak OTP (One-Time Password) generation using only 6 numeric digits combined with a 10-minute validity window and no rate limiting on verification attempts. This make...

CVSS:
8.1
Affected:
up to 1.7.16
Fixed in:
1.7.17
Disclosed:
Dec 15, 2025

CVE-2025-14002 on NVD →

WPCOM Member [wpcom-member] < 1.7.15

unknown

[en] The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the...

Affected:
up to 1.7.15
Fixed in:
1.7.15
Disclosed:
Nov 1, 2025

CVE-2025-11920 on NVD →

WPCOM Member <= 1.7.14 - Authenticated (Contributor+) Local File Inclusion via Shortcode

high

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the serv...

CVSS:
8.8
Affected:
up to 1.7.14
Fixed in:
1.7.15
Disclosed:
Oct 31, 2025

CVE-2025-11920 on NVD →

WPCOM Member <= 1.7.7 - Authenticated (Contributor+) Local File Inclusion

high

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. T...

CVSS:
8.8
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Apr 16, 2025

CVE-2025-39570 on NVD →

WPCOM Member [wpcom-member] < 1.7.8

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Apr 16, 2025

CVE-2025-39570 on NVD →

WPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection

high

The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

CVSS:
7.5
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Mar 13, 2025

CVE-2025-2221 on NVD →

WPCOM Member <= 1.7.5 - Authentication Bypass via 'user_phone'

critical

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an ad...

CVSS:
9.8
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Mar 6, 2025

CVE-2025-1475 on NVD →

WPCOM Member [wpcom-member] < 1.5.4.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPCOM WPCOM Member allows Reflected XSS.This issue affects WPCOM Member: from n/a through 1.5.4.

Affected:
up to 1.5.4.1
Fixed in:
1.5.4.1
Disclosed:
Oct 5, 2024

CVE-2024-47378 on NVD →

WPCOM Member <= 1.5.4 - Reflected Cross-Site Scripting

medium

The WPCOM Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login_redirect' parameter in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 1.5.4
Fixed in:
1.5.4.1
Disclosed:
Sep 30, 2024

CVE-2024-47378 on NVD →

WPCOM Member <= 1.5.2.1 - Unauthenticated Privilege Escalation via User Meta

critical

The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an admin...

CVSS:
9.8
Affected:
up to 1.5.2.1
Fixed in:
1.5.3
Disclosed:
Sep 6, 2024

CVE-2024-7493 on NVD →

WPCOM Member [wpcom-member] < 1.5.3

unknown

[en] The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Sep 6, 2024

CVE-2024-7493 on NVD →

Several WordPress.org Plugins <= Various Versions - Injected Backdoor

critical

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...

CVSS:
10
Affected:
1.3.15 – 1.3.15, 1.3.16 – 1.3.16
Fixed in:
1.3.14
Disclosed:
Jun 24, 2024

CVE-2024-6297 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database