Medium 4.3
2026-02-09< 2.11.9
CVE-2025-15147
Minimum safe version
2.11.9
Update to 2.11.9 or later to address 5 fixable vulnerabilities
CVE-2025-15147
CVE-2023-2276
WordPress WCFM Membership Plugin <= 2.9.10 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress WCFM Membership Plugin <= 2.10.0 is vulnerable to Broken Access Control
WordPress WCFM Membership Plugin <= 2.10.0 is vulnerable to Privilege Escalation