Strangerstudios
strangerstudios
26 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Nov 1, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jul 30, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jul 30, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jul 9, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jun 19, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jun 19, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missi...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 May 2, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Apr 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Apr 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Apr 9, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missi...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Mar 11, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jan 25, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missin...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jan 11, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly imp...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Nov 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and inc...Show more |
Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions. |
1Strangerstudios 1Memberlite Shortcodes Jun 17, 2026 Oct 31, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Oct 20, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function....Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Mar 20, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Feb 13, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to p...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Jan 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. |