Home/Product/reputeinfosystems armember
Product

reputeinfosystems armember

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-47425
< 3.4.11
Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Securit
4.3MEDIUM
CVE-2023-39994
< 5.9.3
Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control
4.3MEDIUM
CVE-2022-47424
< 4.0.6
Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-S
5.4MEDIUM
CVE-2023-47837
< 4.0.11
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember
8.3HIGH
CVE-2023-51356
< 4.0.11
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember
8.8HIGH
CVE-2024-32948
< 4.0.29
Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.
9.1CRITICAL
CVE-2024-30223
< 4.0.27
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.2
9.0CRITICAL
CVE-2024-30222
< 4.0.27
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.2
8.5HIGH
CVE-2024-27995
< 4.0.24
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember
5.9MEDIUM
CVE-2024-0969
<= 4.0.24
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via
5.3MEDIUM
CVE-2023-52200
<= 4.0.22
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember - Membership Plu
9.6CRITICAL
CVE-2022-46808
< 4.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember
8.2HIGH
CVE-2023-3996
<= 4.0.14
The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up
4.4MEDIUM
CVE-2022-47421
< 4.0.5
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember (free), Repute InfoSystems ARMember
5.9MEDIUM
CVE-2023-3011
< 4.0.6
The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. This is due
6.5MEDIUM
CVE-2023-33323
<= 4.0.2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember plugin <= 4.0.2 versions.
5.9MEDIUM
CVE-2022-47140
<= 4.0.1
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember plugin <= 4.0.1 versions.
7.1HIGH
CVE-2022-42888
<= 5.5.1
Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
9.8CRITICAL
CVE-2022-1903
< 3.4.8
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and aut
8.1HIGH
threatengine.sh