Skip to content

Known CVE

Paid Memberships Pro < 2.6.6 - Cross-Site Scripting

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-24979

Medium2021CVSS 6.1CWE-79

cve2021 · wp · wordpress · wpscan · wp-plugin · xss · authenticated · strangerstudios

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website