CVE-2025-49333

WordPress Simple Membership <= 4.6.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership allows Stored XSS. This issue affects Simple Membership: from n/a through 4.6.3.


We have discovered 9,237 live websites that are affected by CVE-2025-49333.

Run a Free Instant Scan




Affected Software

Product  Simple Membership
Category Wordpress Plugins
Vulnerable Domains9,237 live websites (93% of Simple Membership install base)
Vulnerable Versions
  • from 0 through 4.6.3
Vulnerable Versions Count58 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 6, 2025
  • Updated - Jun 6, 2025

Credits

  • bintable (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-49333
United States3,086 websites



Germany1,894 websites
Japan1,058 websites
GB424 websites
France370 websites
Switzerland230 websites
Spain223 websites
Cyprus158 websites
Denmark145 websites
Netherlands143 websites

Website Distribution by TLD

Number of websites using CVE-2025-49333
.com3,244 websites
.de1,370 websites
.org1,077 websites
.net282 websites
.jp265 websites
.co.uk251 websites
.ch204 websites
.nl152 websites
.ca151 websites
.es130 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-49333

Top websites that are affected by CVE-2025-49333. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
******.com United States**,***
**********.com **,***
********************.***.uk United States**,***
*******************.com United States**,***
*******.org United States**,***
********.com United States**,***
********************.net United States***,***
********************.org United States***,***
***.***********.com Hungary***,***
See full domain list

FAQ

CVE-2025-49333 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Simple Membership
A total of 9,237 websites have been identified as vulnerable to CVE-2025-49333, based on global website indexing conducted by WebTechSurvey.
The Simple Membership is affected by the CVE-2025-49333 vulnerability.
Simple Membership versions up to and including 4.6.3 are vulnerable to CVE-2025-49333.