Executive brief
WP-Members is a WordPress plugin used to create and manage membership sites with registration controls and access restrictions. The plugin is vulnerable to reflected cross-site scripting (XSS), allowing attackers to inject malicious code into registration pages if a victim visits a specially crafted URL and clicks on the Terms of Service link. This could lead to session hijacking, credential theft, or defacement affecting any site using the plugin.
Technical details
The vulnerability is a reflected XSS flaw stemming from insufficient input sanitization and output escaping of URL query string parameters in the WP-Members Membership Plugin. The vulnerable code is located in the forms handling component (class-wp-members-forms.php). Exploitation requires an attacker to craft a malicious URL and trick a victim into visiting it, then clicking the Terms of Service link on the rendered registration page. This is a low-privileged attack vector (unauthenticated, user-interaction required) that allows injection and execution of arbitrary JavaScript in the victim's browser. Patches are available in versions after 3.5.6.
Affected products
- WP-Members WP-Members Membership Plugin up to and including 3.5.6
Timeline
- 2026-09-11: disclosed