Butlerblog's vulnerability profile centers on WP Members, a WordPress membership and access-control plugin deployed across a notable range of WordPress sites. The recurring exposure reflects application-layer weaknesses characteristic of web plugins: cross-site scripting, missing authorization checks, cross-site request forgery, and improper access control, which are endemic to authentication and membership-management code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Butlerblog over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15660HIGH The wp-members plugin before 3.2.8 for WordPress has CSRF. | Aug 27, 2019 | 8.8 | 26 | NO | NO |
CVE-2025-14448MEDIUM The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions | Jan 15, 2026 | 5.4 | 20 | NO | NO |
CVE-2024-1852MEDIUM The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due | Apr 9, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-9231MEDIUM The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all | Oct 22, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-10374MEDIUM The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3 | Oct 25, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1987MEDIUM The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due t | Mar 8, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-6733MEDIUM The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. Thi | Jan 4, 2024 | 6.5 | 17 | NO | NO |
CVE-2017-2222MEDIUM Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jul 7, 2017 | 6.1 | 17 | NO | NO |
CVE-2023-2869MEDIUM The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions u | Jul 12, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Butlerblog.
Media articles that mention a CVE ID that affects a product developed by Butlerblog — matched by CVE ID, not by vendor name.