Skip to content
Noroxi

strangerstudios records

26 published records for vendor strangerstudios.

All records

26 records
  • CVE-2023-23488
    67This week

    The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' para

    CriticalCVSS 9.8WeaponizedEPSS 92%

    strangerstudios · paid memberships proJan 20, 2023

  • CVE-2021-25114
    64This week

    Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 82%

    strangerstudios · paid memberships proFeb 7, 2022

  • Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection

    HighCVSS 8.8No exploitEPSS 60%

    strangerstudios · paid memberships proMar 20, 2023

  • Paid Memberships Pro <= 2.12.3 - Authenticated (Subscriber+) Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 51%

    strangerstudios · paid memberships proNov 17, 2023

  • Paid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 65%

    strangerstudios · paid memberships proFeb 13, 2023

  • WordPress Paid Memberships Pro plugin <= 3.0.4 - Insecure Direct Object References (IDOR) vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    strangerstudios · paid memberships proNov 1, 2024

  • SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary S

    HighCVSS 8.8No exploitEPSS 2%

    strangerstudios · paid memberships proMar 17, 2021

  • WordPress Paid Memberships Pro plugin <= 1.2.3 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    strangerstudios · paid memberships proJun 19, 2024

  • WordPress Force First and Last Name as Display Name Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    strangerstudios · force display nameNov 12, 2023

  • WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    strangerstudios · paid memberships proApr 24, 2024

  • WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    strangerstudios · paid memberships proApr 24, 2024

  • CVE-2020-5579
    28Monitor

    SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary S

    HighCVSS 7.2No exploitEPSS 1%

    strangerstudios · paid memberships proMay 20, 2020

  • WordPress Paid Memberships Pro plugin <= 3.0.5 - Authenticated SQL Injection vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    strangerstudios · paid memberships proJul 9, 2024

  • CVE-2024-1287
    26Monitor

    Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

    MediumCVSS 6.5No exploitEPSS 1%

    strangerstudios · paid memberships proJul 30, 2024

  • CVE-2014-8801
    25Monitor

    Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attac

    MediumCVSS 5.0Proof of conceptEPSS 18%

    strangerstudios · paid memberships proNov 28, 2014

  • CVE-2015-5532
    25Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote att

    MediumCVSS 6.1No exploitEPSS 2%

    strangerstudios · paid memberships proOct 23, 2017

  • Paid Memberships Pro < 2.6.6 - Reflected Cross-Site Scripting

    MediumCVSS 6.1Proof of conceptEPSS 2%

    strangerstudios · paid memberships proDec 27, 2021

  • CVE-2024-0624
    21Monitor

    Paid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Update

    MediumCVSS 5.3Proof of conceptEPSS 1%

    strangerstudios · paid memberships proJan 24, 2024

  • CVE-2023-6855
    21Monitor

    Paid Memberships Pro <= 2.12.5 - Missing Authorization via API

    MediumCVSS 5.3No exploitEPSS 1%

    strangerstudios · paid memberships proJan 11, 2024

  • CVE-2023-5237
    21Monitor

    Memberlite Shortcodes < 1.3.9 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    strangerstudios · memberlite shortcodesOct 31, 2023

  • CVE-2024-1407
    21Monitor

    Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modification

    MediumCVSS 5.4No exploitEPSS 0%

    strangerstudios · paid memberships proJun 19, 2024

  • CVE-2024-1286
    19Monitor

    Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure

    MediumCVSS 4.9No exploitEPSS 1%

    strangerstudios · paid memberships proJul 30, 2024

  • CVE-2024-0588
    17Monitor

    Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery

    MediumCVSS 4.3Proof of conceptEPSS 1%

    strangerstudios · paid memberships proApr 9, 2024

  • CVE-2024-1279
    17Monitor

    Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosure

    MediumCVSS 4.3No exploitEPSS 1%

    strangerstudios · paid memberships proMar 11, 2024

  • Paid Memberships Pro <= 2.4.2 - Cross-Site Request Forgery Bypass

    MediumCVSS 4.3No exploitEPSS 0%

    strangerstudios · paid memberships proOct 20, 2023