CVE · High

CVE-2019-14328 — Simple Membership [simple-membership] < 3.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-14328 Simple Membership [simple-membership] < 3.8.5 Cross-Site Request Forgery (CSRF) High 8.8 < 3.8.5 3.8.5 2019-07-27

CVE-2019-14328

The Simple Membership plugin for WordPress contained a cross-site request forgery vulnerability in versions up to and including 3.8.4, discovered by a researcher named rubyman. This flaw allowed attackers to perform unauthorized actions on behalf of authenticated users by tricking them into visiting a malicious webpage. The vulnerability was addressed in version 3.8.5 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.