Plugin Vulnerability Hub
Plugin 7 known issues Latest disclosed Apr 21, 2025

Memberpress Vulnerabilities

Review known vulnerability records for the WordPress plugin Memberpress (`memberpress`), including severity, CVE references, affected versions, and patch status.

Known Records
7
High or Critical
1
Linked CVEs
7
Last Updated
Aug 15, 2025
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Memberpress so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
7 records include a published patch path.
Severity Mix
0 critical and 1 high severity finding.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Memberpress

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2024-11299
Memberpress <= 1.11.37 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restr...

Published
Apr 21, 2025
Patched Release
1.12.0
Affected Versions
Versions up to 1.11.37
Next Step
Update to 1.12.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-39407
Memberpress < 1.12.0 - Reflected Cross-Site Scripting

The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 1.12.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Published
Apr 17, 2025
Patched Release
1.12.0
Affected Versions
Versions before 1.12.0
Next Step
Update to 1.12.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5024
MemberPress <= 1.11.29 - Reflected Cross-Site Scripting via mepr_screenname and mepr_key Parameters

The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthentic...

Published
Aug 29, 2024
Patched Release
1.11.30
Affected Versions
Versions up to 1.11.29
Next Step
Update to 1.11.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43956
Memberpress <= 1.11.34 - Missing Authorization

The Memberpress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.11.34. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Aug 26, 2024
Patched Release
1.11.35
Affected Versions
Versions up to 1.11.34
Next Step
Update to 1.11.35 or newer if supported.
Plugin High Patched: Yes CVE-2024-5031
MemberPress <= 1.11.29 - Authenticated (Contributor+) Blind Server-Side Request Forgery via mepr-user-file Shortcode

The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web reque...

Published
May 21, 2024
Patched Release
1.11.30
Affected Versions
Versions up to 1.11.29
Next Step
Update to 1.11.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5025
MemberPress <= 1.11.29 - Authenticated (Contributor+) Stored Cross-Site Scripting via arglist Parameter

The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrib...

Published
May 21, 2024
Patched Release
1.11.30
Affected Versions
Versions up to 1.11.29
Next Step
Update to 1.11.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1412
Memberpress <= 1.11.24 - Reflected Cross-Site Scripting via message and error

The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac...

Published
Mar 21, 2024
Patched Release
1.11.27
Affected Versions
Versions up to 1.11.26
Next Step
Update to 1.11.27 or newer if supported.