Cross Site Scripting Vulnerability in WishList Member Plugin by WishList
CVE-2026-57384

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-57384?

A significant Cross Site Scripting (XSS) vulnerability has been identified in the WishList Member plugin, specifically affecting versions up to 3.32.0. This flaw allows malicious actors to inject scripts into web pages viewed by users. Exploiting this vulnerability can lead to unauthorized actions on behalf of users, including stealing sensitive information or executing harmful scripts. It poses a serious security risk for WordPress websites utilizing this plugin, highlighting the importance of keeping software up to date and implementing robust security measures.

Affected Version(s)

WishList Member X <= 3.32.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Austin Ginder | Patchstack Bug Bounty Program
.