← WordPress Vulnerabilities
WordPress security by component

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jan 14, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: membership-content-restriction-paid-member-subscriptions

CVE-2024-12919: Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction: Privilege escalation or authentication bypass

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.

PublishedJan 14, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 14, 2025 CVE-2024-12919
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction: Privilege escalation or authentication bypass
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Dec 18, 2024 CVE-2024-11291
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction: Sensitive information exposure
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Nov 09, 2024 CVE-2024-10261
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction: A security weakness
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVDPending
Sep 13, 2021 CVE-2021-24728
Membership & Content Restriction – Paid Member Subscriptions: SQL injection
Membership & Content Restriction – Paid Member Subscriptions is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8