Wishlistmember develops a membership and access-control plugin for WordPress sites, with its vulnerability exposure centered on authorization and code-execution weaknesses such as improper privilege management, code injection, and missing authorization checks. These issues reflect the plugin's role in mediating content access and user permissions within WordPress environments, where input validation and access-control enforcement are critical to security posture.
The number and severity of CVEs published that impact products developed by Wishlistmember over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37112CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: fr | Jul 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-37109HIGH Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/ | Jun 24, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37107HIGH Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7. | Jun 24, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37111HIGH Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. | Jun 24, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wishlistmember.
Media articles that mention a CVE ID that affects a product developed by Wishlistmember — matched by CVE ID, not by vendor name.