← WordPress Vulnerabilities
WordPress security by component

WPCOM Member

WPCOM Member is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Dec 16, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: wpcom-member

CVE-2025-14002: WPCOM Member: Privilege escalation or authentication bypass

WPCOM Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.

PublishedDec 16, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 16, 2025 CVE-2025-14002
WPCOM Member: Privilege escalation or authentication bypass
WPCOM Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVDPending
Nov 01, 2025 CVE-2025-11920
WPCOM Member: Filesystem traversal
WPCOM Member is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Apr 16, 2025 CVE-2025-39570
WPCOM Member: Filesystem traversal
WPCOM Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Mar 14, 2025 CVE-2025-2221
WPCOM Member: SQL injection
WPCOM Member is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Mar 07, 2025 CVE-2025-1475
WPCOM Member: Privilege escalation or authentication bypass
WPCOM Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Oct 05, 2024 CVE-2024-47378
WPCOM Member: Cross-site scripting
WPCOM Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Sep 06, 2024 CVE-2024-7493
WPCOM Member: Privilege escalation or authentication bypass
WPCOM Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending