The wp-eMember WordPress plugin before 10.6.7 does not...
Moderate severity
Unreviewed
Published
Jul 13, 2024
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
Jul 13, 2024
Published to the GitHub Advisory Database
Jul 13, 2024
Last updated
May 6, 2025
The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks
References