Pricing
Case studies
Login
Start trial
WP-Members
Chad Butler
Developer
3.5.6
Latest version
50,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
17 patched
3 Mitigation rules
Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute vulnerability
<= 3.5.5.1
03/03/2026
Missing Authorization to Sensitive Information Exposure vulnerability
<= 3.4.8
16/02/2026
Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields vulnerability
<= 3.5.4.3
15/01/2026
Unauthenticated Information Exposure via Unprotected Files vulnerability
<= 3.5.4.4
06/01/2026
Cross Site Scripting (XSS) Vulnerability
<= 3.5.4.2
22/09/2025
Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names vulnerability
<= 3.5.4.2
08/09/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 3.5.4.1
21/07/2025
Cross Site Scripting (XSS) Vulnerability
<= 3.5.4
19/06/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_memberships Shortcode vulnerability
<= 3.5.2
16/05/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode vulnerability
<= 3.4.9.5
25/10/2024
Reflected Cross-Site Scripting vulnerability
<= 3.4.9.5
21/10/2024
Unprotected Storage of Potentially Sensitive Files vulnerability
<= 3.4.9.3
26/04/2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 3.4.9.2
01/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.4.9.1
08/03/2024
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.2.7
16/06/2019
Stored XSS
<= 2.8.9
01/08/2014
Reflected XSS
<= 2.8.9
01/08/2014