strangerstudios CVE Vulnerabilities & Metrics

Focus on strangerstudios vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About strangerstudios Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with strangerstudios. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total strangerstudios CVEs: 22
Earliest CVE date: 28 Nov 2014, 15:59 UTC
Latest CVE date: 01 Nov 2024, 15:15 UTC

Latest CVE reference: CVE-2024-37277

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 9

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 50.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical strangerstudios CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.48

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 17
4.0-6.9 5
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS strangerstudios CVEs

These are the five CVEs with the highest CVSS scores for strangerstudios, sorted by severity first and recency.

All CVEs for strangerstudios

CVE-2024-37277 strangerstudios vulnerability CVSS: 0 01 Nov 2024, 15:15 UTC

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

CVE-2024-37486 strangerstudios vulnerability CVSS: 0 09 Jul 2024, 09:15 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.

CVE-2023-39990 strangerstudios vulnerability CVSS: 0 19 Jun 2024, 13:15 UTC

Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

CVE-2024-1407 strangerstudios vulnerability CVSS: 0 19 Jun 2024, 07:15 UTC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to subscribe to, modify, or cancel membership for a user via a forged request granted they can trick a user into performing an action such as clicking on a link.

CVE-2024-3215 strangerstudios vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it possible for unauthenticated attackers to update order levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-32794 strangerstudios vulnerability CVSS: 0 24 Apr 2024, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

CVE-2024-32793 strangerstudios vulnerability CVSS: 0 24 Apr 2024, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

CVE-2024-0588 strangerstudios vulnerability CVSS: 0 09 Apr 2024, 19:15 UTC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible for unauthenticated attackers to enable the streamline setting with Lifter LMS via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-1279 strangerstudios vulnerability CVSS: 0 11 Mar 2024, 18:15 UTC

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

CVE-2024-0624 strangerstudios vulnerability CVSS: 0 25 Jan 2024, 02:15 UTC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-6855 strangerstudios vulnerability CVSS: 0 11 Jan 2024, 09:15 UTC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.

CVE-2023-6187 strangerstudios vulnerability CVSS: 0 18 Nov 2023, 02:15 UTC

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if 2Checkout (deprecated since version 2.6) or PayPal Express is set as the payment method and a custom user field is added that is only visible at profile, and not visible at checkout according to its settings.

CVE-2023-28419 strangerstudios vulnerability CVSS: 0 12 Nov 2023, 23:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.

CVE-2020-36754 strangerstudios vulnerability CVSS: 0 20 Oct 2023, 08:15 UTC

The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0631 strangerstudios vulnerability CVSS: 0 20 Mar 2023, 16:15 UTC

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

CVE-2022-4830 strangerstudios vulnerability CVSS: 0 13 Feb 2023, 15:15 UTC

The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-23488 strangerstudios vulnerability CVSS: 0 20 Jan 2023, 18:15 UTC

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CVE-2021-25114 strangerstudios vulnerability CVSS: 7.5 07 Feb 2022, 16:15 UTC

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVE-2021-24979 strangerstudios vulnerability CVSS: 4.3 27 Dec 2021, 11:15 UTC

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-20678 strangerstudios vulnerability CVSS: 6.5 18 Mar 2021, 01:15 UTC

SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2020-5579 strangerstudios vulnerability CVSS: 6.5 20 May 2020, 11:15 UTC

SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

CVE-2015-5532 strangerstudios vulnerability CVSS: 4.3 23 Oct 2017, 18:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to adminpages/membershiplevels.php.

CVE-2014-8801 strangerstudios vulnerability CVSS: 5.0 28 Nov 2014, 15:59 UTC

Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.