WordPress security by component
WishList Member X
Plugin description
WishList Member X is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 17, 2026; the highest CVE/CNA score is 10.
Plugin slug:
wishlist-member-xLatest vulnerability
CVE-2026-25446: WishList Member X: Dangerous file upload
WishList Member X is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 3.29.0.
| Safe version |
|
||
|---|---|---|---|
| Jun 17, 2026 |
CVE-2026-25446
WishList Member X: Dangerous file upload
WishList Member X is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 3.29.0.
|
> 3.29.0 |
CVE9.9
NVDPending
|
| Jun 17, 2026 |
CVE-2026-24575
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.29.0.
|
> 3.29.0 |
CVE4.3
NVDPending
|
| Mar 19, 2026 |
CVE-2026-25445
WishList Member X: Code execution
WishList Member X is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37108
WishList Member X: Filesystem traversal
WishList Member X is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.7
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37106
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.2
NVDPending
|
| Jul 10, 2024 |
CVE-2024-37113
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jul 10, 2024 |
CVE-2024-37110
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jul 09, 2024 |
CVE-2024-37112
WishList Member X: SQL injection
WishList Member X is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE10.0
NVD9.8
|
| Jun 24, 2024 |
CVE-2024-37111
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jun 24, 2024 |
CVE-2024-37109
WishList Member X: Code execution
WishList Member X is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Jun 24, 2024 |
CVE-2024-37107
WishList Member X: Privilege escalation or authentication bypass
WishList Member X is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVD8.8
|