← WordPress Vulnerabilities
WordPress security by component

Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is a WordPress component with 23 published CVE records in this archive. The latest tracked vulnerability was published May 02, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: paid-memberships-pro

CVE-2026-4100: Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: A security weakness

Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.5.

PublishedMay 02, 2026
Known safe version> 3.6.5
Safe version
May 02, 2026 CVE-2026-4100
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: A security weakness
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.5.
> 3.6.5
CVE7.1
NVDPending
Nov 01, 2024 CVE-2024-37277
Paid Memberships Pro: A security weakness
Paid Memberships Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD9.8
Jul 30, 2024 CVE-2024-1287
pmpro-member-directory: A security weakness
pmpro-member-directory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jul 30, 2024 CVE-2024-1286
pmpro-membership-maps: A security weakness
pmpro-membership-maps is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVDPending
Jul 09, 2024 CVE-2024-37486
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Jun 19, 2024 CVE-2024-1407
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
May 02, 2024 CVE-2024-3215
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD4.3
Apr 24, 2024 CVE-2024-32794
Paid Memberships Pro: Cross-site request forgery
Paid Memberships Pro is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 24, 2024 CVE-2024-32793
Paid Memberships Pro: Cross-site request forgery
Paid Memberships Pro is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Apr 09, 2024 CVE-2024-0588
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 11, 2024 CVE-2024-1279
Paid Memberships Pro: A security weakness
Paid Memberships Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Jan 25, 2024 CVE-2024-0624
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD5.3
Jan 11, 2024 CVE-2023-6855
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: A security weakness
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 18, 2023 CVE-2023-6187
Paid Memberships Pro: Dangerous file upload
Paid Memberships Pro is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.5
NVD8.8
Oct 20, 2023 CVE-2020-36754
Paid Memberships Pro: Cross-site request forgery
Paid Memberships Pro is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Mar 20, 2023 CVE-2023-0631
Paid Memberships Pro: A security weakness
Paid Memberships Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Feb 13, 2023 CVE-2022-4830
Paid Memberships Pro: Cross-site scripting
Paid Memberships Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD5.4
Jan 20, 2023 CVE-2023-23488
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Feb 07, 2022 CVE-2021-25114
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Dec 27, 2021 CVE-2021-24979
Paid Memberships Pro: Cross-site scripting
Paid Memberships Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 18, 2021 CVE-2021-20678
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Oct 23, 2017 CVE-2015-5532
Paid Memberships Pro: Cross-site scripting
Paid Memberships Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Nov 28, 2014 CVE-2014-8801
Paid Memberships Pro: Filesystem traversal
Paid Memberships Pro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.0
NVD5.0