Medium 5.4 Closed
2024-06-19< 1.2.4
CVE-2023-39990
CVE-2023-39990
WordPress Paid Memberships Pro Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)
Paid Memberships Pro - Courses for Membership Add On <= 1.2.3 - Cross-Site Request Forgery to Course Modifications
Paid Memberships Pro - Courses for Membership Add On <= 1.2.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Paid Memberships Pro - Courses for Membership Add On <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Course Modifications
Premium Courses & eLearning <= 1.0.5 - SQL Injection