CVE-2024-3730
The Simple Membership plugin for WordPress contains a stored cross-site scripting vulnerability in the 'swpm_paypal_subscription_cancel_link' shortcode affecting versions through 4.4.3. Authenticated contributors and higher-level users can inject malicious scripts into pages through insufficiently sanitized shortcode attributes, and these scripts execute for any visitor accessing the affected page. The vulnerability stems from a lack of proper input validation and output encoding. Version 4.4.4 and later address this flaw.
Based on public CVE data (MITRE/NVD).