The wp-eMember WordPress plugin before 10.3.9 does not...
High severity
Unreviewed
Published
Jun 4, 2024
to the GitHub Advisory Database
•
Updated Jun 17, 2025
Description
Published by the National Vulnerability Database
Jun 4, 2024
Published to the GitHub Advisory Database
Jun 4, 2024
Last updated
Jun 17, 2025
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
References