← WordPress Vulnerabilities
WordPress security by component

WishList Member X

WishList Member X is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 17, 2026; the highest CVE/CNA score is 10.

Plugin slug: wishlist-member-x

CVE-2026-25446: WishList Member X: Dangerous file upload

WishList Member X is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 3.29.0.

PublishedJun 17, 2026
Known safe version> 3.29.0
Safe version
Jun 17, 2026 CVE-2026-25446
WishList Member X: Dangerous file upload
WishList Member X is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 3.29.0.
> 3.29.0
CVE9.9
NVDPending
Jun 17, 2026 CVE-2026-24575
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.29.0.
> 3.29.0
CVE4.3
NVDPending
Mar 19, 2026 CVE-2026-25445
WishList Member X: Code execution
WishList Member X is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Nov 01, 2024 CVE-2024-37108
WishList Member X: Filesystem traversal
WishList Member X is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.7
NVDPending
Nov 01, 2024 CVE-2024-37106
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVDPending
Jul 10, 2024 CVE-2024-37113
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Jul 10, 2024 CVE-2024-37110
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jul 09, 2024 CVE-2024-37112
WishList Member X: SQL injection
WishList Member X is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE10.0
NVD9.8
Jun 24, 2024 CVE-2024-37111
WishList Member X: A security weakness
WishList Member X is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jun 24, 2024 CVE-2024-37109
WishList Member X: Code execution
WishList Member X is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.9
NVD8.8
Jun 24, 2024 CVE-2024-37107
WishList Member X: Privilege escalation or authentication bypass
WishList Member X is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8