← WordPress Vulnerabilities
WordPress security by component

MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet

MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 28, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: paid-membership

CVE-2025-5937: MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet: Cross-site request forgery

MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedJun 28, 2025
Safe version guidanceSee mitigation notes
Safe version
Jun 28, 2025 CVE-2025-5937
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet: Cross-site request forgery
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 28, 2025 CVE-2025-31075
MicroPayments: Cross-site scripting
MicroPayments is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Mar 26, 2025 CVE-2025-26579
MicroPayments: Cross-site scripting
MicroPayments is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Apr 20, 2022 CVE-2022-27629
Paid Membership: Cross-site request forgery
Paid Membership is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8