Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial
Plugin Icon

WP-Members

Chad Butler

Developer

3.5.4.3

Latest version

50,000

Installations

Sep 4, 2025

Last updated

WordPress Plugin
Active VDP
Report vulnerability
    VulnerabilitiesSecurity PolicySecurity Contributors

Vulnerability history

0 present
13 fixed
3 Mitigation rules
  • Cross Site Scripting (XSS) Vulnerability
    <= 3.5.4.2
    Sep 22, 2025
  • Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names vulnerability
    <= 3.5.4.2
    Sep 8, 2025
  • Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
    <= 3.5.4.1
    Jul 21, 2025
  • Cross Site Scripting (XSS) Vulnerability
    <= 3.5.4
    Jun 19, 2025
  • Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_user_memberships Shortcode vulnerability
    <= 3.5.2
    May 16, 2025
  • Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode vulnerability
    <= 3.4.9.5
    Oct 25, 2024
  • Reflected Cross-Site Scripting vulnerability
    <= 3.4.9.5
    Oct 21, 2024
  • Unprotected Storage of Potentially Sensitive Files vulnerability
    <= 3.4.9.3
    Apr 26, 2024
  • Unauthenticated Stored Cross-Site Scripting vulnerability
    <= 3.4.9.2
    Apr 1, 2024
  • Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
    <= 3.4.9.1
    Mar 8, 2024
  • Cross-Site Request Forgery (CSRF) vulnerability
    <= 3.2.7
    Jun 16, 2019
  • Stored XSS
    <= 2.8.9
    Aug 1, 2014
  • Reflected XSS
    <= 2.8.9
    Aug 1, 2014

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag