Search Results (5 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19709 2 Wordpress, Wpswings 2 Wordpress, Membership For Woocommerce 2026-08-21 5.3 Medium
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.
CVE-2025-67909 2 Wordpress, Wpswings 2 Wordpress, Membership For Woocommerce 2026-04-27 7.5 High
Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Membership For WooCommerce: from n/a through <= 3.0.3.
CVE-2025-54692 2 Wordpress, Wpswings 2 Wordpress, Membership For Woocommerce 2025-08-14 7.5 High
Missing Authorization vulnerability in WP Swings Membership For WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Membership For WooCommerce: from n/a through 2.9.0.
CVE-2025-49265 1 Wpswings 1 Membership For Woocommerce 2025-06-24 7.5 High
Missing Authorization vulnerability in WP Swings Membership For WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Membership For WooCommerce: from n/a through 2.8.1.
CVE-2022-4395 1 Wpswings 1 Membership For Woocommerce 2025-03-27 9.8 Critical
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.