Impact
The WP‑Members Membership Plugin allows an unauthenticated attacker to inject malicious scripts into the registration page via an unsanitized URL query string. This typical reflected XSS flaw (CWE‑79) means that any user who clicks a crafted link and then clicks the Terms of Service link on the page will have the injected script executed in their browser with the user’s privileges. The consequences can include session hijacking, data theft, or defacement of the site.
Affected Systems
All WordPress sites that have the WP‑Members Membership Plugin version 3.5.6 or earlier installed, regardless of the site owner or host, are affected.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and EPSS data is not available. The vulnerability does not appear in the CISA KEV catalog, but the attack vector is straightforward: a phishing email or a malicious link that a victim follows, followed by a click on the Terms of Service link to trigger script execution. Given the ease of social engineering, the practical risk to exposed installations is significant despite the moderate baseline score.
OpenCVE Enrichment