CVE · Medium

CVE-2024-4383 — Simple Membership [simple-membership] < 4.4.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4383 Simple Membership [simple-membership] < 4.4.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.4.6 4.4.6 2024-05-03

CVE-2024-4383

The Simple Membership plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions up to 4.4.5 in the 'swpm_paypal_subscription_cancel_link' shortcode, where insufficient sanitization and escaping of user-supplied shortcode attributes allows authenticated contributors and higher-privileged users to embed malicious scripts into pages that execute when viewed by any visitor.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.