Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
Simple Membership
Minimum safe version
4.7.2
Update to 4.7.2 or later to address 29 fixable vulnerabilities
Simple Membership <= 4.7.1 - Missing Authorization
CVE-2026-25308
CVE-2025-49333
CVE-2024-11088
CVE-2024-49682
CVE-2024-4383
CVE-2024-3730
CVE-2024-1985
CVE-2024-22308
WordPress Simple Membership Plugin <= 4.3.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-6882
CVE-2023-41957
CVE-2023-41956
CVE-2023-4719
Simple Membership <= 3.2.8 - Cross-Site Scripting (XSS)
Simple Membership < 3.2.9 - Reflected Cross-Site Scripting
CVE-2022-4469
Simple Membership <= 4.0.3 - Authenticated (Admin+) SQL Injections
CVE-2022-2317
CVE-2022-2273
CVE-2022-1724
WordPress Simple Membership Plugin <= 3.2.8 - Cross Site Scripting (XSS)
WordPress Simple Membership plugin <= 4.0.3 - Authenticated SQL Injection (SQLi) vulnerability
CVE-2022-0681
WordPress Simple Membership plugin <= 3.8.4 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2017-18499
CVE-2016-10884
CVE-2022-0328