FAPI Member

FAPI Member has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).

The one issue recorded for FAPI Member has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by NumeX. FAPI Member is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all FAPI Member vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2025-66132

FAPI Member <= 2.2.29 - Unauthenticated Insecure Direct Object Reference

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv2.2.37
4.0(2)
80/100
Last Updated
2026-09-02 (11d ago)
Active Installs
500+
Downloads
25,574
Requires WP
5.9+
Requires PHP
8.1+
Tested up to
WP 6.7.7
Created
2021-03-30 (6y ago)

Plugin FAPI Member umožňuje jednoduchou správu členských sekcí, tedy webových stránek přístupných jen oprávněným uživatelům. Ve spojení s aplikací FAPI tak můžete velmi snadno a automatizovaně prodávat přístup do svých on-line kurzů, klubů nebo k prémiovému obsahu na svém webu. Dále přidává jednoduchou možnost vkládání prodejního formuláře skrze WordPress komponentu FAPI form. Seznam nekompatibilních pluginů: – WP Cerber Security, Anti-spam & Malware Scan => Zakazuje FM vytvořit uživatele Ohodnoťte tento plugin a dejte nám zpětnou vazbu Ohodnotit tento plugin můžete na stránkách WordPress.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C