Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership allows Stored XSS. This issue affects Simple Membership: from n/a through 4.6.3.
We have discovered 9,237 live websites that are affected by CVE-2025-49333.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 9,237 live websites (93% of Simple Membership install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 58 versions ( 98% of all versions) |
![]() | 3,086 websites |
![]() | 1,894 websites |
![]() | 1,058 websites |
![]() | 424 websites |
![]() | 370 websites |
![]() | 230 websites |
![]() | 223 websites |
![]() | 158 websites |
![]() | 145 websites |
![]() | 143 websites |
.com | 3,244 websites |
.de | 1,370 websites |
.org | 1,077 websites |
.net | 282 websites |
.jp | 265 websites |
.co.uk | 251 websites |
.ch | 204 websites |
.nl | 152 websites |
.ca | 151 websites |
.es | 130 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
**********.com | **,*** | ||
********************.***.uk | ![]() | **,*** | |
*******************.com | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
********************.net | ![]() | ***,*** | |
********************.org | ![]() | ***,*** | |
***.***********.com | ![]() | ***,*** |
FAQ