Caseproof develops a focused line of WordPress plugins for membership, affiliate marketing, and link management that are widely deployed across small-to-medium business and creator websites. The vulnerability profile centers on web-application input-handling and authorization weaknesses—cross-site scripting, CSRF, SQL injection, and missing authorization controls—that are endemic to plugin-based extensions operating within shared WordPress environments, and the vendor's disclosures show an elevated tendency toward public exploit availability. Defenders should prioritize keeping affected plugins updated and monitor for derivative attacks targeting users of the MemberPress, PrettyLinks, and Thirsty Affiliates products; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Caseproof over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4595MEDIUM Pretty-Link WordPress plugin 1.5.2 has XSS | Jan 10, 2020 | 6.1 | 32 | NO | YES |
CVE-2024-43956CRITICAL Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1 | Nov 1, 2024 | 9.8 | 25 | NO | NO |
CVE-2013-1636MEDIUM Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNew | Mar 12, 2014 | 4.3 | 23 | NO | YES |
CVE-2024-11299HIGH The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress core search feature. This makes | Apr 22, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-5031MEDIUM The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes | May 22, 2024 | 6.4 | 20 | NO | NO |
CVE-2021-24127MEDIUM Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross- | Mar 18, 2021 | 5.4 | 19 | NO | NO |
CVE-2015-9457HIGH The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter. | Oct 10, 2019 | 7.2 | 19 | NO | NO |
CVE-2024-5025MEDIUM The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient inpu | May 22, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-1412MEDIUM The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to i | Apr 9, 2024 | 6.1 | 17 | NO | NO |
CVE-2022-0634MEDIUM The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscri | Apr 25, 2022 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Caseproof.
Media articles that mention a CVE ID that affects a product developed by Caseproof — matched by CVE ID, not by vendor name.