Vulnerabilities > Armemberplugin > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-20 | CVE-2023-3996 | Cross-site Scripting vulnerability in Armemberplugin Armember The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. | 4.8 |
2023-07-18 | CVE-2022-47421 | Cross-site Scripting vulnerability in Armemberplugin Armember Auth. | 4.8 |
2022-06-27 | CVE-2022-1903 | Missing Authorization vulnerability in Armemberplugin Armember The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username | 6.8 |