Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Strangerstudios

First CVE: Nov 28, 2014Active for: 12 yearsTotal CVEs: 28
44.7
VTI Score
High

Strangerstudios develops a focused line of WordPress membership and access-control plugins that extend the core platform's functionality for subscription management and content protection, placing them in a high-exposure position across a large installed base. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding elevated tendency to acquire public exploit tooling, reflecting the sensitivity of authentication and authorization logic in membership systems. The exposure recurs across products such as Paid Memberships Pro, Force Display Name, and Memberlite Shortcodes through weakness classes including cross-site request forgery, SQL injection, cross-site scripting, and missing authorization checks that are characteristic of web application layers handling user data and access boundaries. Defenders should treat this vendor's security updates as high-priority for any WordPress deployment relying on membership or role-based access control; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Strangerstudios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 28, 2014
11 years ago
Most Recent CVE
Sep 17, 2025
310 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-23488CRITICAL
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST rout
Jan 20, 20239.893NOYES
CVE-2021-25114CRITICAL
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL stat
Feb 7, 20229.883NOYES
CVE-2023-0631HIGH
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
Mar 20, 20238.860NONO
CVE-2023-6187HIGH
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fie
Nov 18, 20238.855NONO
CVE-2022-4830MEDIUM
The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow user
Feb 13, 20235.451NONO
CVE-2014-8801MEDIUM
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (d
Nov 28, 20145.038NOYES
CVE-2021-24979MEDIUM
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site
Dec 27, 20216.131NOYES
CVE-2021-20678HIGH
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Mar 18, 20218.827NONO
CVE-2024-37277CRITICAL
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Membe
Nov 1, 20249.826NONO
CVE-2024-32794HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
Apr 24, 20248.824NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
57%
32%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (96.4%)
Unknown1 (3.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High0 (0.0%)
Unknown1 (3.6%)
User Interaction
None16 (57.1%)
Unknown1 (3.6%)
Required11 (39.3%)
Privileges Required
Low10 (35.7%)
High3 (10.7%)
None14 (50.0%)
Unknown1 (3.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.6% of CVEs· 98th percentile
Nuclei
3 CVEs
10.7% of CVEs· 96th percentile
ExploitDB
2 CVEs
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Strangerstudios.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Strangerstudios — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Strangerstudios's Products

View all 6 CNAs →

Top CWEs