Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.1epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Simple Membershippublic PoCs found — 1
cve_referencewpscan.com/vulnerability/30779ecc-779c-4e7c-9e8b-278ddf343214/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.