S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 12, 2026

CVE-2024-13727 Scanner

CVE-2024-13727 Scanner - Cross-Site Scripting (XSS) vulnerability in MemberSpace WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-13727
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
MemberSpace
AFFECTED< 2.1.14SAFE ✓≥ 2.1.14
Updated Aug 22, 2026View on NVD →
Detail

MemberSpace is a prominent plugin used in WordPress to manage memberships and subscriptions effectively. It's utilized by website administrators and content creators to gate premium content and manage user access. The plugin aids in setting up paywalls and subscription-based content delivery to enhance monetization strategies. Users find it beneficial for creating tiered access levels and managing member login and registration seamlessly. Many online platforms rely on MemberSpace to handle complex membership plans and billing cycles. The plugin integrates smoothly with various payment gateways and other WordPress features to provide an integrated solution for membership management.

Cross-Site Scripting (XSS) is a prevalent security vulnerability found in web applications, where attackers inject malicious scripts into trusted websites viewed by other users. In the context of MemberSpace WordPress, the vulnerability exists due to unsanitized input output that allows an attacker to execute scripts in another user's browser. This flaw is significant because it can lead to unauthorized actions on behalf of the user or data theft. Typically, XSS vulnerabilities can be exploited to steal session cookies, redirect users to malicious sites, or carry out phishing attacks. Addressing such vulnerabilities is crucial to maintaining the integrity and trust of web platforms. XSS remains a top concern due to its potential impact on user security and privacy.

The vulnerability in MemberSpace WordPress involves improper handling of unsanitized and unescaped parameter outputs. This occurs on certain endpoints within the plugin's architecture, specifically noted in the notification bar functional area. Attackers aim to inject scripts through manipulation of these unsanitized parameters. Once injected, the scripts execute within the browser context of any user viewing the compromised web page. This vulnerability is particularly dangerous as it does not require authentication for exploitation. Addressing the vulnerability requires updating to a secure version where parameter sanitization routines are enforced.

Exploiting this XSS vulnerability can lead to unauthorized script execution in a user's browser, potentially compromising sensitive information. The impact includes theft of user credentials, session hijacking, and broader account control by attackers. It can also result in users being redirected to harmful websites, leading to further exploitation or phishing attacks. Moreover, the vulnerability may allow attackers to perform actions on behalf of the logged-in user, causing unauthorized alterations or access to protected resources. Such exploitation tarnishes user trust and can have reputational and financial repercussions for the site owner.

REFERENCES

Solution Advice
  • Update the MemberSpace WordPress plugin to version 2.1.14 or later.
  • Implement input validation and sanitization to prevent injection of malicious scripts.
  • Use Content Security Policy (CSP) to restrict execution of scripts to trusted sources.
  • Regularly audit and monitor web applications for potential security vulnerabilities.
  • Educate users on recognizing and avoiding interactions with potentially harmful links or scripts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.