Ontraport's vulnerability footprint centers on a narrowly scoped set of membership and publishing products, with observed weaknesses concentrated in application-layer input handling and access control, specifically SQL injection and missing authorization flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ontraport over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1002010CRITICAL Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it d | Sep 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-1002009CRITICAL Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it d | Sep 14, 2017 | 9.8 | 28 | NO | NO |
CVE-2024-23524HIGH Missing Authorization vulnerability in ONTRAPORT Inc. PilotPress.This issue affects PilotPress: from n/a through 2.0.30. | Jun 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-58238MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ONTRAPORT PilotPress pilotpress allows Stored XSS.This issue affects PilotPres | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-58221MEDIUM Missing Authorization vulnerability in ONTRAPORT PilotPress pilotpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PilotPress: from n | Sep 22, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ontraport.
Media articles that mention a CVE ID that affects a product developed by Ontraport — matched by CVE ID, not by vendor name.