Membership Content Restriction Paid Member Subscriptions Cozmoslabs Membership Content Restriction Paid Member Subscriptions

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Cozmoslabs Membership Content Restriction Paid Member Subscriptions.

By the Year

In 2026 there have been 0 vulnerabilities in Cozmoslabs Membership Content Restriction Paid Member Subscriptions. Last year, in 2025 Membership Content Restriction Paid Member Subscriptions had 1 security vulnerability published. Right now, Membership Content Restriction Paid Member Subscriptions is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 1 9.80
2024 5 5.66
2023 0 0.00
2022 0 0.00
2021 1 8.80

It may take a day or so for new Membership Content Restriction Paid Member Subscriptions vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Cozmoslabs Membership Content Restriction Paid Member Subscriptions Security Vulnerabilities

WordPress Paid Membership Subscriptions Auth Bypass v<=2.13.7
CVE-2024-12919 9.8 - Critical - January 14, 2025

The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.

authentification

WordPress Paid Membership Subscriptions Plugin Sensitive Information Exposure via Search
CVE-2024-11291 5.3 - Medium - December 18, 2024

The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as logged-in users.

Information Disclosure

Effortless Memberships Shortcode Execution Flaw
CVE-2024-10261 7.3 - High - November 09, 2024

The The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Code Injection

Paid Membership Subscriptions (<=2.12.8) Reflected XSS via add_query_arg
CVE-2024-9222 6.1 - Medium - October 02, 2024

The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

XSS

WP PaidMembershipSubs v2.11.1 missing capability, pricing table creation
CVE-2024-1390 4.3 - Medium - February 29, 2024

The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create pricing tables.

AuthZ

WP Paid Membership Subscriptions 2.11.1 Cap Check Bypass
CVE-2024-1389 5.3 - Medium - February 29, 2024

The Paid Membership Subscriptions Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1. This makes it possible for unauthenticated attackers to change the Stripe payment keys.

AuthZ

The Membership & Content Restriction Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise
CVE-2021-24728 8.8 - High - September 13, 2021

The Membership & Content Restriction Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Cozmoslabs Membership Content Restriction Paid Member Subscriptions or by Cozmoslabs? Click the Watch button to subscribe.

Cozmoslabs
Vendor

subscribe