WordPress Restrict User Access – Membership Plugin with Force versions before 2.6 is vulnerable to Reflected Cross-Site Scripting via the '_rua_section' parameter in the admin level edit page.
id: CVE-2024-29138
info:
name: WordPress Restrict User Access <= 2.5 - Cross-Site Scripting
aut
...