CVE-2025-49333Cross-site Scripting in Simple Membership

Severity
5.5MEDIUM
No vector
EPSS
0.2%
top 60.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership simple-membership allows Stored XSS.This issue affects Simple Membership: from n/a through <= 4.6.3.

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
WordPress Simple Membership plugin <= 4.6.3 - Cross Site Scripting (XSS) Vulnerability2025-06-06
GHSA
GHSA-p9ph-6ww4-r598: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp2025-06-06

📋Vendor Advisories

1
Microsoft
net/mlx5: E-Switch, pair only capable devices2025-02-11
CVE-2025-49333 — Cross-site Scripting | cvebase