Medium 6.3
2024-10-16< 2.2.2
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Minimum safe version
2.6
Update to 2.6 or later to address 7 fixable vulnerabilities
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-29138
CVE-2024-0687
WordPress Restrict User Access – Membership Plugin with Force Plugin < 2.4.3 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Restrict User Access – Membership Plugin with Force plugin <= 2.2.1 - Sensitive Information Disclosure vulnerability
WordPress Restrict User Access – Membership Plugin with Force plugin <= 2.2.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability