WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction

Feature-packed membership plugin for creating subscription plans, adding recurring payments & content restriction on your membership site.

20Reported vulnerabilities
9.8Highest CVSS score
3.0.8Latest version
10,000+Active installs

What to do now

Update Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction to 3.0.8 or later. 20 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 5, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24728 High 8.8 1.7% Before 2.4.2 2.4.2 September 13, 2021
CVE-2024-12919 Critical 9.8 0.6% Before 2.13.8 2.13.8 January 14, 2025
CVE-2025-54017 High 8.1 0.4% 2.15.4 and earlier 2.15.5 July 29, 2025
CVE-2025-49870 High 7.5 0.2% 2.15.1 and earlier 2.15.2 July 3, 2025
CVE-2024-10261 High 7.3 0.5% Before 2.13.1 2.13.1 November 9, 2024
CVE-2025-31088 Medium 6.4 0.2% 2.14.3 and earlier 2.14.4 March 28, 2025
CVE-2026-57348 Medium 6.1 0.3% 3.0.4 and earlier 3.0.5 July 1, 2026
CVE-2026-39514 Medium 6.1 0.2% 2.17.3 and earlier 3.0.0 April 20, 2026
CVE-2024-9222 Medium 6.1 0.4% Before 2.12.9 2.12.9 October 2, 2024
WF-89614950-8517-4765-886a-1aa30a2f052e Medium 6.1 Before 2.4.2 2.4.2 August 6, 2021
CVE-2024-1389 Medium 5.3 0.5% Before 2.11.2 2.11.2 February 29, 2024
CVE-2025-11835 Medium 5.3 0.2% 0 to 2.16.4 (inclusive) 2.16.5 November 5, 2025
CVE-2025-58600 Medium 5.3 0.4% 2.15.9 and earlier 2.16.0 September 3, 2025
CVE-2024-11291 Medium 5.3 0.5% Before 2.13.5 2.13.5 December 18, 2024
CVE-2024-1390 Medium 4.3 0.5% Before 2.11.2 2.11.2 February 29, 2024
CVE-2026-14848 Medium 4.3 0.2% 3.0.7 and earlier 3.0.8 July 27, 2026
CVE-2026-59539 Medium 4.3 0.3% 3.0.7 and earlier 3.0.8 July 23, 2026
CVE-2026-14847 Medium 4.3 0.2% 3.0.6 and earlier 3.0.7 July 13, 2026
CVE-2025-68514 Medium 4.3 0.3% 2.16.8 and earlier 2.16.9 February 11, 2026
CVE-2023-51522 Medium 4.3 0.2% 2.10.4 and earlier 2.10.5 December 27, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.