WP-Members <= 3.5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP-Members Membership Plugin
Minimum safe version
3.5.6
Update to 3.5.6 or later to address 23 fixable vulnerabilities
WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names
WP-Members Membership Plugin <= 3.5.5.1 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute
CVE-2025-14448
CVE-2025-12648
WP-Members <= 3.5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-50051
WP-Members <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_memberships Shortcode
CVE-2024-10374
CVE-2024-9231
CVE-2024-2920
CVE-2024-1852
CVE-2024-1987
CVE-2023-6733
WP-Members 2.8.9 - wp-login.php register Action Multiple Parameter Reflected XSS
WP-Members 2.8.9 - profile.php Multiple Parameter Stored XSS
CVE-2023-2869
WP-Members Membership Plugin <= 2.8.9 - Reflected Cross-Site Scripting
WordPress Members Plugin <= 2.8.9 - Reflected XSS
WordPress Members Plugin <= 2.8.9 - Stored XSS
WordPress WP-Members plugin <= 3.2.7 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2017-2222
CVE-2019-15660