Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP-Members Membership Plugin — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in WP-Members Membership Plugin, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting the WP-Members Membership Plugin, a popular WordPress tool for creating user registration and membership systems. It aggregates vulnerability data related to common weakness types such as cross-site scripting, unauthorized access, and SQL injection that have been identified within the plugin’s codebase. The collected entries cover reported issues ranging from early releases up to the most recent updates, ensuring a comprehensive view of the product’s security history. Readers can use this resource to track the vendor’s advisory responses over time, understand the specific implications of each weakness class on their site’s integrity, and look up the product’s full vulnerability history to assess long-term maintenance quality. By reviewing these details, administrators can better evaluate the risks associated with the plugin version currently in use. This information serves as a reference for security audits and patch management decisions. The page focuses solely on factual vulnerability records without endorsing or criticizing the vendor, providing a neutral overview for developers and site owners. Understanding these past issues helps in configuring the plugin more securely and staying informed about potential exposure. This aggregation allows for a clear assessment of how the product has evolved in response to security challenges.

Vendor: cbutlerjr

CVE IDTitleCVSSSeverityPublished
CVE-2026-2363 WP-Members Membership Plugin <= 3.5.5.1 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute CWE-89 6.5 Medium2026-03-04
CVE-2025-14448 WP-Members Membership Plugin <= 3.5.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields CWE-79 5.4 Medium2026-01-15
CVE-2025-12648 WP-Members Membership Plugin <= 3.5.4.4 - Unauthenticated Information Exposure via Unprotected Files CWE-552 5.3 Medium2026-01-07
CVE-2025-9489 WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names CWE-94 5.0 Medium2025-09-09
CVE-2025-7495 WP-Members <= 3.5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-07-22
CVE-2025-4610 WP-Members <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_memberships Shortcode CWE-79 6.4 Medium2025-05-17
CVE-2024-10374 WP-Members <= 3.4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode CWE-79 6.4 Medium2024-10-25
CVE-2024-9231 WP-Members Membership Plugin <= 3.4.9.5 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2024-10-22
CVE-2024-2920 WP-Members Membership Plugin <= 3.4.9.3 - Unprotected Storage of Potentially Sensitive Files CWE-200 5.3 Medium2024-04-26
CVE-2024-1852 WP-Members Membership Plugin <= 3.4.9.2 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2024-04-09
CVE-2024-1987 WP-Members Membership Plugin <= 3.4.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2024-03-08
CVE-2023-6733 WP-Members Membership Plugin <= 3.4.8 - Missing Authorization to Sensitive Information Exposure CWE-284 6.5 Medium2024-01-04
CVE-2023-2869 WP-Members Membership <= 3.4.7.3 - Missing Authorization to Settings Update CWE-862 4.3 Medium2023-07-12

All 13 known CVE vulnerabilities affecting WP-Members Membership Plugin with full Chinese analysis, references, and POCs where available.