SecAlerts
p

paid memberships pro

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 20, 2024 to present

13
Total CVEs
6
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
33/100
low

Severity Distribution

Critical
1
High
5
Medium
7
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
CSRF
2
2
Code Injection
1
3
SQL Injection
1

Most Affected Products

1. Strangerstudios Paid Memberships Pro Wordpress7
2. Paid Memberships Pro Paid Memberships Pro5
3. Cozmoslabs Membership \& Content Restriction - Paid Member Subscriptions Wordpress3
4. WordPress Paid Memberships Pro3
5. Paid Memberships Pro Memberships – Effortless Memberships, Recurring Payments & Content Restriction1

Recent Vulnerabilities

See more →
CVE-2025-11835
CVSS 5.3medium

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.16.4 - Missing Authorization to Unauthenticated Arbitrary Member Subscription Auto Renewal

Nov 5, 2025🔧 No Patch
CVE-2024-10261
CVSS 7.3high

Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution

Nov 9, 2024
CVE-2024-37277
CVSS 9.8critical

WordPress Paid Memberships Pro plugin <= 3.0.4 - Insecure Direct Object References (IDOR) vulnerability

Nov 1, 2024
CVE-2024-1287
CVSS 6.5medium

Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

Jul 30, 2024🔧 No Patch
CVE-2024-1286
CVSS 4.9medium

Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure

Jul 30, 2024🔧 No Patch
CVE-2023-39990
CVSS 8.8high

WordPress Paid Memberships Pro plugin <= 1.2.3 - Broken Access Control vulnerability

Jun 19, 2024
CVE-2023-40608
CVSS 8.2high

WordPress Paid Memberships Pro CCBill Gateway plugin <= 0.3 - Unauthenticated Broken Access Control vulnerability

Jun 19, 2024
CVE-2024-32793
CVSS 8.8EPSS 0%high

WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerability

Apr 24, 2024
CVE-2024-32794
CVSS 8.8EPSS 0%high

WordPress Paid Memberships Pro plugin <= 2.12.10 - Cross Site Request Forgery (CSRF) vulnerability

Apr 24, 2024
CVE-2024-30514
CVSS 5.3EPSS 0%medium

WordPress Paid Memberships Pro – Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File vulnerability

Mar 29, 2024

Monitor paid memberships pro in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

paid memberships pro Security Vulnerabilities & Risk Score | 13 CVEs | SecAlerts - SecAlerts