WordPress Paid Memberships Pro Plugin <= 3.6.5 is vulnerable to a medium priority Broken Access Control
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
CVE-2024-37486
CVE-2024-37277
Paid Memberships Pro < 2.12.7 - Information Exposure in Debug Logs
CVE-2024-1407
CVE-2024-32793
CVE-2024-32794
CVE-2024-3215
CVE-2024-0588
CVE-2024-1279
WordPress Paid Memberships Pro Plugin <= 2.12.8 is vulnerable to Sensitive Data Exposure
Paid Memberships Pro <= 2.12.8 - Authenticated (Contributor+) User Meta Disclosure
CVE-2024-0624
WordPress Paid Memberships Pro Plugin <= 2.12.6 is vulnerable to Sensitive Data Exposure
Paid Memberships Pro <= 2.12.6 - Information Exposure in Debug Logs
WordPress Paid Memberships Pro Plugin <= 2.12.5 is vulnerable to Broken Access Control
CVE-2023-6187
Paid Memberships Pro 1.4.7 - adminpages/memberslist-csv.php Direct Request Member Personal Information Disclosure
Paid Memberships Pro <= 2.0.5 - Authenticated Open Redirect
Paid Memberships Pro < 2.3.3 - Authenticated SQL Injection
Paid Memberships Pro < 2.5.1 - Authenticated Cross-Site Scripting (XSS)
Paid Membership Pro < 2.5.3 - Unauthorised Order Information Disclosure
Paid Membership Pro < 2.5.10 - Cross-Site Scripting (XSS)
CVE-2020-36754
CVE-2021-4342
CVE-2023-0631
CVE-2022-4830
CVE-2023-23488
Paid Memberships Pro <= 2.0.5 - Open Redirect
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Paid Memberships Pro <= 2.5.0 - Cross-Site Scripting
Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.2 - IDOR to Sensitive Information Disclosure
Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.9.1 - Cross-Site Scripting
Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF)
WordPress Paid Memberships Pro Plugin <= 1.4.7 - Information Disclosure
WordPress Paid Memberships Pro plugin <= 2.0.5 - Authenticated Open Redirect vulnerability
WordPress Paid Memberships Pro plugin <= 2.4.2 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Paid Memberships Pro plugin <= 2.5 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress Paid Memberships Pro plugin <= 2.5.2 - Insecure Direct Object Reference & sensitive information disclosure vulnerability
CVE-2020-5579
CVE-2014-8801
CVE-2015-5532
CVE-2021-20678
CVE-2021-24979
CVE-2021-25114