Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32997 | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 29 Jan 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cozmoslabs membership \& Content Restriction - Paid Member Subscriptions
|
|
| CPEs | cpe:2.3:a:cozmoslabs:membership_\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Cozmoslabs membership \& Content Restriction - Paid Member Subscriptions
|
Tue, 12 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cozmoslabs
Cozmoslabs paid Member Subscriptions |
|
| CPEs | cpe:2.3:a:cozmoslabs:paid_member_subscriptions:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cozmoslabs
Cozmoslabs paid Member Subscriptions |
|
| Metrics |
ssvc
|
Sat, 09 Nov 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
| Title | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-11-12T18:30:55.938Z
Reserved: 2024-10-22T20:12:16.856Z
Link: CVE-2024-10261
Updated: 2024-11-12T18:30:49.209Z
Status : Analyzed
Published: 2024-11-09T12:15:16.800
Modified: 2025-01-29T19:16:00.153
Link: CVE-2024-10261
No data.
OpenCVE Enrichment
No data.
EUVD