Description
The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34548 | The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:32:09.608Z
Reserved: 2022-06-30T00:00:00.000Z
Link: CVE-2022-2273
No data.
Status : Modified
Published: 2022-08-01T13:15:10.957
Modified: 2024-11-21T07:00:39.913
Link: CVE-2022-2273
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD