Vulnerabilities > Strangerstudios

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-37277 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
network
low complexity
strangerstudios
critical
9.8
2024-07-09 CVE-2024-37486 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
network
low complexity
strangerstudios
7.2
2024-06-19 CVE-2023-39990 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
network
low complexity
strangerstudios
8.8
2024-05-02 CVE-2024-3215 Cross-Site Request Forgery (CSRF) vulnerability in Strangerstudios Paid Memberships PRO
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1.
network
low complexity
strangerstudios CWE-352
4.3
2024-04-24 CVE-2024-32793 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
network
low complexity
strangerstudios
8.8
2024-04-24 CVE-2024-32794 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
network
low complexity
strangerstudios
8.8
2024-03-11 CVE-2024-1279 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
network
low complexity
strangerstudios
4.3
2024-01-25 CVE-2024-0624 Cross-Site Request Forgery (CSRF) vulnerability in Strangerstudios Paid Memberships PRO
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7.
network
low complexity
strangerstudios CWE-352
5.3
2024-01-11 CVE-2023-6855 Missing Authorization vulnerability in Strangerstudios Paid Memberships PRO
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive).
network
low complexity
strangerstudios CWE-862
5.3
2023-11-18 CVE-2023-6187 Unrestricted Upload of File with Dangerous Type vulnerability in Strangerstudios Paid Memberships PRO
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3.
network
low complexity
strangerstudios CWE-434
8.8