Simple Membership WordPress Simple Membership

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in WordPress Simple Membership.

By the Year

In 2026 there have been 0 vulnerabilities in WordPress Simple Membership. Simple Membership did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 1 5.40

It may take a day or so for new Simple Membership vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent WordPress Simple Membership Security Vulnerabilities

WP Simple Membership <=4.4.3 Stored XSS via swpm_paypal_sub_cancel_link
CVE-2024-3730 5.4 - Medium - April 25, 2024

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for WordPress Simple Membership or by WordPress? Click the Watch button to subscribe.

WordPress
Vendor

subscribe