Vulnerabilities > Simple Membership Plugin > Simple Membership > 4.4.5

DATE CVE VULNERABILITY TITLE RISK
2024-11-21 CVE-2024-11088 Information Exposure vulnerability in Simple-Membership-Plugin Simple Membership
The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature.
network
low complexity
simple-membership-plugin CWE-200
7.5
2024-10-24 CVE-2024-49682 Open Redirect vulnerability in Simple-Membership-Plugin Simple Membership
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership allows Phishing.This issue affects Simple Membership: from n/a through 4.5.3.
network
low complexity
simple-membership-plugin CWE-601
6.1
2024-05-14 CVE-2024-4383 Cross-site Scripting vulnerability in Simple-Membership-Plugin Simple Membership
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
simple-membership-plugin CWE-79
5.4