WordPress security by component
Paid Memberships Pro
Plugin description
Paid Memberships Pro creates membership levels, restricts content, manages member accounts, and handles recurring membership subscriptions in WordPress.
Paid Memberships Pro (paid-memberships-pro) is a WordPress plugin with 23 published CVE records in this archive. The latest tracked vulnerability was published May 02, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
paid-memberships-proLatest vulnerability
CVE-2026-4100: Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: A security weakness
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.5.
| Safe version |
|
||
|---|---|---|---|
| May 02, 2026 |
CVE-2026-4100
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: A security weakness
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.5.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37277
Paid Memberships Pro: A security weakness
Paid Memberships Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD9.8
|
| Jul 30, 2024 |
CVE-2024-1287
pmpro-member-directory: A security weakness
pmpro-member-directory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 30, 2024 |
CVE-2024-1286
pmpro-membership-maps: A security weakness
pmpro-membership-maps is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Jul 09, 2024 |
CVE-2024-37486
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jun 19, 2024 |
CVE-2024-1407
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| May 02, 2024 |
CVE-2024-3215
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Apr 24, 2024 |
CVE-2024-32794
Paid Memberships Pro: Cross-site request forgery
Paid Memberships Pro is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 24, 2024 |
CVE-2024-32793
Paid Memberships Pro: Cross-site request forgery
Paid Memberships Pro is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Apr 09, 2024 |
CVE-2024-0588
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 11, 2024 |
CVE-2024-1279
Paid Memberships Pro: A security weakness
Paid Memberships Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jan 25, 2024 |
CVE-2024-0624
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Cross-site request forgery
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Jan 11, 2024 |
CVE-2023-6855
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: A security weakness
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Nov 18, 2023 |
CVE-2023-6187
Paid Memberships Pro: Dangerous file upload
Paid Memberships Pro is affected by dangerous file upload. Exploitation requires an authenticated subscriber account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Oct 20, 2023 |
CVE-2020-36754
Paid Memberships Pro: Cross-site request forgery
Paid Memberships Pro is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 20, 2023 |
CVE-2023-0631
Paid Memberships Pro: A security weakness
Paid Memberships Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Feb 13, 2023 |
CVE-2022-4830
Paid Memberships Pro: Cross-site scripting
Paid Memberships Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD5.4
|
| Jan 20, 2023 |
CVE-2023-23488
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 07, 2022 |
CVE-2021-25114
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Dec 27, 2021 |
CVE-2021-24979
Paid Memberships Pro: Cross-site scripting
Paid Memberships Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Mar 18, 2021 |
CVE-2021-20678
Paid Memberships Pro: SQL injection
Paid Memberships Pro is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Oct 23, 2017 |
CVE-2015-5532
Paid Memberships Pro: Cross-site scripting
Paid Memberships Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Nov 28, 2014 |
CVE-2014-8801
Paid Memberships Pro: Filesystem traversal
Paid Memberships Pro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD5.0
|