Strangerstudios develops a focused line of WordPress membership and access-control plugins that extend the core platform's functionality for subscription management and content protection, placing them in a high-exposure position across a large installed base. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding elevated tendency to acquire public exploit tooling, reflecting the sensitivity of authentication and authorization logic in membership systems. The exposure recurs across products such as Paid Memberships Pro, Force Display Name, and Memberlite Shortcodes through weakness classes including cross-site request forgery, SQL injection, cross-site scripting, and missing authorization checks that are characteristic of web application layers handling user data and access boundaries. Defenders should treat this vendor's security updates as high-priority for any WordPress deployment relying on membership or role-based access control; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Strangerstudios over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23488CRITICAL The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST rout | Jan 20, 2023 | 9.8 | 93 | NO | YES |
CVE-2021-25114CRITICAL The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL stat | Feb 7, 2022 | 9.8 | 83 | NO | YES |
CVE-2023-0631HIGH The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query. | Mar 20, 2023 | 8.8 | 60 | NO | NO |
CVE-2023-6187HIGH The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fie | Nov 18, 2023 | 8.8 | 55 | NO | NO |
CVE-2022-4830MEDIUM The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow user | Feb 13, 2023 | 5.4 | 51 | NO | NO |
CVE-2014-8801MEDIUM Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (d | Nov 28, 2014 | 5.0 | 38 | NO | YES |
CVE-2021-24979MEDIUM The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site | Dec 27, 2021 | 6.1 | 31 | NO | YES |
CVE-2021-20678HIGH SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | Mar 18, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-37277CRITICAL Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Membe | Nov 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-32794HIGH Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. | Apr 24, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Strangerstudios.
Media articles that mention a CVE ID that affects a product developed by Strangerstudios — matched by CVE ID, not by vendor name.