CVE-2022-2273

Severity
8.8HIGH
EPSS
0.7%
top 28.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateAug 2

Description

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-hfj7-fhvx-37c9: The Simple Membership WordPress plugin before 42022-08-02
CVEList
Simple Membership < 4.1.3 - Membership Privilege Escalation2022-08-01
CVE-2022-2273 (HIGH CVSS 8.8) | The Simple Membership WordPress plu | cvebase.io