Skip to main content

Vendor/product archive

tipsandtricks-hq / wp_emember CVEs

Beta · best-effort

10 CVEs tagged to tipsandtricks-hq / wp_emember0 Critical, 4 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-5081

Published Aug 5, 2024

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5744

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5715

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5080

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5079

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5077

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5076

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5075

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5074

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4749

Published Jun 4, 2024

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripti…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1