Beta

Report

WishList Member X < 3.26.7 is vulnerable to Unautenticated Plugin Settings Change Leading to Stored XSS vulnerability

Unauthenticated
Published
2024-06-19

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the a function in all versions up to, and including, 3.25.1. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts.

CVSS

Score:8.2

Severity:High

Version:< 3.26.7

There is a patch available in v3.26.7 and we strongly recommend you update to this version as soon as possible.