Strangerstudios
Strangerstudios Paid Memberships PRO: vulnerabilidades y CVE
Strangerstudios Paid Memberships PRO tiene 25 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses1
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15016 | Media (6.4) | 0.26% | — | 28 jul 2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode… |
| CVE-2024-37277 | Crítica (9.8) | 0.67% | — | 1 nov 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. |
| CVE-2024-1287 | Media (6.5) | 0.52% | — | 30 jul 2024 | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. |
| CVE-2024-1286 | Media (4.9) | 0.56% | — | 30 jul 2024 | The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. |
| CVE-2024-37486 | Alta (7.2) | 0.74% | — | 9 jul 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5. |
| CVE-2023-39990 | Alta (8.8) | 0.48% | — | 19 jun 2024 | Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. |
| CVE-2024-1407 | Media (5.4) | 0.22% | — | 19 jun 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to… |
| CVE-2024-3215 | Media (4.3) | 0.30% | — | 2 may 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to… |
| CVE-2024-32794 | Alta (8.8) | 0.24% | — | 24 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. |
| CVE-2024-32793 | Alta (8.8) | 0.23% | — | 24 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. |
| CVE-2024-0588 | Media (4.3) | 0.90% | — | 9 abr 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to… |
| CVE-2024-1279 | Media (4.3) | 0.55% | — | 11 mar 2024 | The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata. |
| CVE-2024-0624 | Media (5.3) | 0.95% | — | 25 ene 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to… |
| CVE-2023-6855 | Media (5.3) | 0.51% | — | 11 ene 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly… |
| CVE-2023-6187 | Alta (8.8) | 51% | — | 18 nov 2023 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and… |
| CVE-2020-36754 | Media (4.3) | 0.39% | — | 20 oct 2023 | The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function.… |
| CVE-2023-0631 | Alta (8.8) | 60% | — | 20 mar 2023 | The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query. |
| CVE-2022-4830 | Media (5.4) | 65% | — | 13 feb 2023 | The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to… |
| CVE-2023-23488 | Crítica (9.8) | 92% | — | 20 ene 2023 | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. |
| CVE-2021-25114 | Crítica (9.8) | 82% | — | 7 feb 2022 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection |
| CVE-2021-24979 | Media (6.1) | 1.9% | — | 27 dic 2021 | The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
| CVE-2021-20678 | Alta (8.8) | 2.0% | — | 18 mar 2021 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2020-5579 | Alta (7.2) | 1.2% | — | 20 may 2020 | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2015-5532 | Media (6.1) | 2.1% | — | 23 oct 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to… |
| CVE-2014-8801 | Media (5) | 18% | — | 28 nov 2014 | Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.