Klubraum Membership Request
Klubraum Membership Request has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Klubraum Membership Request has a vendor fix available, so running the current release closes it.
All of these findings were reported by Md. Moniruzzaman Prodhan (NomanProdhan). Klubraum Membership Request is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-4604Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update
Read the full analysisVulnerability Records
Klubraum Membership Request
Author
klubraum
Klubraum is a modern app for communication and organization of large private groups, like sports clubs, NGOs, etc. Find out more on klubraum.com This plugin provides a widget as shortcode to be integrated somewhere in your wordpress site. The widget displays a form through which new members can ask to join the group within the Klubraum app. The user is asked to fill in their e-mail address. Thereafter, an e-mail validation mail is sent, from which the membership request can be finally submitted.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C