CVE-2025-12018
Published
CVSS v3
4.4
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS
Description
The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
<p><a href="https://membershipworks.com/" rel="nofollow ugc">MembershipWorks</a> is an advanced all-in-one membership, directory, events, and donation platform for chambers, associations, professional, networking and other membership groups. This plugin integrates your MembershipWorks account to your WordPress site. MembershipWorks is free for small groups and also free to try with our 50 member/account plan.</p>
<h4>Easy WordPress Setup</h4>
<ul>
<li>Use shortcodes to place the membership forms, events calendar, member directory and more on pages.</li>
<li>Fully responsive and works with most themes</li>
</ul>
<h4>Third Party Integrations</h4>
<ul>
<li>Payment Gateways – Stripe, Paypal Website Payments Pro, Paypal Payments Pro/Payflow, Paypal Expanded Checkout, Authorize.net</li>
<li>Accounting Software – Xero, QuickBooks Desktop, QuickBooks Online</li>
<li>Emails/Newsletters – MailChimp</li>
<li>OAuth 2.0 Single Sign On</li>
</ul>
<h4>Membership</h4>
<ul>
<li>Unlimited membership levels, add-ons and billing configurations</li>
<li>Configurable pro-rating, fixed anniversary dates, trial periods, application fees and discount codes</li>
<li>Members can signup, renew, or upgrade/downgrade their membership at any time</li>
<li>Automated emails for payment receipts, renewal and past-due notices</li>
<li>Segment members by labels or folders</li>
<li>View/Export metrics and financials</li>
<li>Daily membership report email</li>
<li>Send bulk emails to members</li>
<li>Custom fields and customizable membership forms</li>
</ul>
<h4>Events</h4>
<ul>
<li>Display events in calendar or list</li>
<li>Upcoming events widget</li>
<li>Event categories</li>
<li>Create unlimited paid and free event tickets</li>
<li>Limit event ticket quantity, event capacity, event tickets per registration, and more</li>
<li>Restrict event tickets by membership</li>
<li>Customizable event registration and ticketing questions</li>
<li>Automatic event registration confirmation email with iCalendar attachment</li>
<li>Edit or cancel registrations and issue full or partial refunds </li>
</ul>
<h4>Member Only Access</h4>
<ul>
<li>Restrict content on any page or post to members or to specific membership levels with a shortcode</li>
<li>Member only event tickets or cart items</li>
<li>Automatically retire access when membership is past due</li>
<li>Allow members to add or edit events</li>
</ul>
<h4>Directory and Deals</h4>
<ul>
<li>Search by keyword, location, fields or by labels/folders</li>
<li>Interactive map</li>
<li>Multiple locations for a business or organization</li>
<li>Customizable cards</li>
<li>Customizable member profiles with logos, pictures, map, social media links and more</li>
<li>Enable/disable features by membership</li>
<li>Create a member deals or offers page</li>
<li>Comply with CAN-SPAM act and protect member email addresses from spam with our messaging system</li>
<li>Member slideshow widget</li>
</ul>
<h4>General Forms, Shopping Cart and Donations</h4>
<ul>
<li>Create forms for donations, committee or volunteer signup, contact forms, and more</li>
<li>Sell items or collect donations</li>
<li>Setup item quantities and checkout limits</li>
<li>Create member only forms or shopping carts</li>
<li>Automated confirmation and notification emails</li>
<li>Checkout actions to add or remove labels/folders, allows for advanced workflow</li>
</ul>
<h4>Job Board, Classifieds and Announcements</h4>
<ul>
<li>Create boards for jobs, classifieds, announcements and other listings</li>
<li>Monetize listings by charging listing fee or make it a membership privilege</li>
<li>Restrict listings to members only or make it public </li>
<li>Option to require admin approval for new listings</li>
<li>Allow members to manage their own listings</li>
</ul>
<h4>Billing and Accounting</h4>
<ul>
<li>Financial dashboard</li>
<li>Setup tax rates by city, state, zip or country</li>
<li>Export transactions to Xero, QuickBooks or spreadsheet</li>
</ul>
<h4>SEO</h4>
<ul>
<li>Events and directory listings optimized with Rich Snippets</li>
</ul>