Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial
Plugin Icon

ARMember

N/A

Developer

N/A

Latest version

N/A

Installations

N/A

Last updated

WordPress Plugin
No VDP
Claim ownership
Report vulnerability
    Vulnerabilities

Vulnerability history

0 present
19 fixed
10 Mitigation rules
  • Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
    <= 4.0.51
    Dec 6, 2024
  • Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload vulnerability
    <= 4.0.37
    Aug 19, 2024
  • Open Redirect vulnerability
    <= 4.0.30
    Apr 30, 2024
  • Broken Access Control vulnerability
    <= 4.0.28
    Apr 22, 2024
  • Directory Traversal via X-FILENAME vulnerability
    <= 4.0.27
    Apr 8, 2024
  • Unauthenticated PHP Object Injection vulnerability
    <= 4.0.26
    Mar 26, 2024
  • PHP Object Injection vulnerability
    <= 4.0.26
    Mar 26, 2024
  • Cross Site Scripting (XSS) vulnerability
    <= 4.0.23
    Mar 15, 2024
  • Improper Access Control to Sensitive Information Exposure via REST API vulnerability
    <= 4.0.24
    Feb 2, 2024
  • Cross Site Request Forgery (CSRF) to PHP Object Injection vulnerability
    <= 4.0.22
    Jan 3, 2024
  • Privilege Escalation vulnerability
    <= 4.0.10
    Dec 26, 2023
  • Membership Plan Bypass vulnerability
    <= 4.0.10
    Nov 16, 2023
  • Cross Site Request Forgery (CSRF)
    <= 4.0.5
    Jul 10, 2023
  • Stored Cross Site Scripting (XSS) on Common Messages Settings
    <= 4.0.4
    Jun 27, 2023
  • Cross Site Scripting (XSS) vulnerability
    <= 4.0.2
    Jun 13, 2023
  • Cross Site Scripting (XSS)
    <= 4.0.1
    Apr 19, 2023
  • SQL Injection (SQLi)
    <= 3.4.11
    Mar 27, 2023
  • Broken Access Control
    <= 3.4.10
    Jan 20, 2023
  • Unauthenticated Admin Account Takeover vulnerability
    <= 3.4.7
    Jun 6, 2022

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag