FAPI Member
FAPI Member has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).
The one issue recorded for FAPI Member has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by NumeX. FAPI Member is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-66132FAPI Member <= 2.2.29 - Unauthenticated Insecure Direct Object Reference
Read the full analysisVulnerability Records
FAPI Member
Author
FAPI Business s.r.o.
Plugin FAPI Member umožňuje jednoduchou správu členských sekcí, tedy webových stránek přístupných jen oprávněným uživatelům. Ve spojení s aplikací FAPI tak můžete velmi snadno a automatizovaně prodávat přístup do svých on-line kurzů, klubů nebo k prémiovému obsahu na svém webu. Dále přidává jednoduchou možnost vkládání prodejního formuláře skrze WordPress komponentu FAPI form. Seznam nekompatibilních pluginů: – WP Cerber Security, Anti-spam & Malware Scan => Zakazuje FM vytvořit uživatele Ohodnoťte tento plugin a dejte nám zpětnou vazbu Ohodnotit tento plugin můžete na stránkách WordPress.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C