Input validation vulnerability in Simple Membership 4.4.5

The Simple Membership plugin for WordPress has a security issue that could allow hackers to insert harmful code onto pages using the plugin’s ‘swpm_paypal_subscription_cancel_link’ feature. This could happen on any version of the plugin up to 4.4.5 because the plugin does not properly protect against malicious code. This means that someone with contributor or higher access could potentially add code that would run when a user opens the affected page.

Detected in:

Simple Membership fixed vulnerable versions: >= * <= 4.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.