CVE · Medium

CVE-2024-3730 — Simple Membership [simple-membership] < 4.4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3730 Simple Membership [simple-membership] < 4.4.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.4.4 4.4.4 2024-04-24

CVE-2024-3730

The Simple Membership plugin for WordPress contains a stored cross-site scripting vulnerability in the 'swpm_paypal_subscription_cancel_link' shortcode affecting versions through 4.4.3. Authenticated contributors and higher-level users can inject malicious scripts into pages through insufficiently sanitized shortcode attributes, and these scripts execute for any visitor accessing the affected page. The vulnerability stems from a lack of proper input validation and output encoding. Version 4.4.4 and later address this flaw.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.