Junglewise Threat Intelligence

CVE-2026-57384: Membership Software WishList Member X Subscriber XSS

CVE-2026-57384 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

WishList Member X is a WordPress plugin used to manage memberships and restrict access to content. A security flaw allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If a site administrator or another visitor views the affected area, these scripts could redirect users to malicious sites, display unauthorized advertisements, or potentially compromise the administrative session.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in WishList Member X versions up to and including 3.32.0 due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires 'Subscriber' level privileges to initiate, but successful exploitation depends on user interaction from a more privileged user (such as an administrator) viewing the injected content. This is a stored XSS attack that allows an attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking or unauthorized site modifications. The issue is resolved in version 3.33.0.

Affected products

  • Membership Software WishList Member X <= 3.32.0

Timeline

  • 2026-05-17: other: Reported by Austin Ginder
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD
  • 2026-07-23: patched: Version 3.33.0 released to address the vulnerability

References