Vulnerabilities (CVE)

Filtered by vendor Strangerstudios Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4830 1 Strangerstudios 1 Paid Memberships Pro 2023-12-28 N/A 5.4 MEDIUM
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2020-36754 1 Strangerstudios 1 Paid Memberships Pro 2023-12-28 N/A 4.3 MEDIUM
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2021-24979 1 Strangerstudios 1 Paid Memberships Pro 2022-01-06 4.3 MEDIUM 6.1 MEDIUM
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2015-5532 1 Strangerstudios 1 Paid Memberships Pro 2021-04-06 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to adminpages/membershiplevels.php.