Strangerstudios
strangerstudios
26 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Feb 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Dec 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Mar 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 May 20, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. |
1Strangerstudios 1Paid Memberships Pro May 13, 2026 Oct 23, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to members...Show more |
1Strangerstudios 1Paid Memberships Pro May 6, 2026 Nov 28, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile...Show more |