tipsandtricks-hq wp_emember CVE Vulnerabilities (10)

CVEs: 10 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting tipsandtricks-hq wp_emember (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-5081 The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack [email protected] 6.1 0.26% 2024-08-05 2025-06-09
CVE-2024-5744 The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers [email protected] 6.8 0.47% 2024-07-13 2025-05-16
CVE-2024-5715 The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin [email protected] 7.1 0.19% 2024-07-13 2025-05-20
CVE-2024-5080 The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server [email protected] 8.8 0.89% 2024-07-13 2025-05-06
CVE-2024-5079 The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks [email protected] 6.1 2.01% 2024-07-13 2025-05-06
CVE-2024-5077 The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack [email protected] 6.8 0.20% 2024-07-13 2025-05-06
CVE-2024-5076 The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks [email protected] 8.8 0.73% 2024-07-13 2025-05-06
CVE-2024-5075 The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin [email protected] 5.9 0.26% 2024-07-13 2025-05-06
CVE-2024-5074 The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin [email protected] 5.4 0.26% 2024-07-13 2025-05-02
CVE-2024-4749 The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. [email protected] 8.3 0.18% 2024-06-04 2025-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence