The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Project Subscriptions

Vendors Products
Cbutlerjr Subscribe
Wp-members Membership Plugin Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 23 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Cbutlerjr
Cbutlerjr wp-members Membership Plugin
CPEs cpe:2.3:a:cbutlerjr:wp-members_membership_plugin:*:*:*:*:*:wordpress:*:*
Vendors & Products Cbutlerjr
Cbutlerjr wp-members Membership Plugin

Thu, 15 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 15 Jan 2026 05:30:00 +0000

Type Values Removed Values Added
Description The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Checkbox and Multiple Select user profile fields in all versions up to, and including, 3.5.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title WP-Members Membership Plugin <= 3.5.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-01-15T14:47:50.023Z

Reserved: 2025-12-10T13:56:57.548Z

Link: CVE-2025-14448

cve-icon Vulnrichment

Updated: 2026-01-15T14:47:46.626Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-15T06:16:05.610

Modified: 2026-01-23T16:06:49.773

Link: CVE-2025-14448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-15T08:03:08Z

Weaknesses