WP-Members Membership Plugin, 8fa7026d8724f0e4f2042248f4d9e27dc71db286
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jan 07, 2014
- Research Description
- WP-Members Membership Plugin [wp-members] < 2.8.10 WP-Members Membership Plugin <= 2.8.9 - Reflected Cross-Site Scripting The WP Members plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 2.8.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected versions
-
max 2.8.10.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Elizaibots (CVE-2025-49893) , Aug 20, 2025 |
| Elizaibots (abcf8d2a13b3fd2324a04f9724e5ac9347743677) , Jun 16, 2026 |