CVE · Medium

CVE-2022-0328 — Simple Membership [simple-membership] < 4.0.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0328 Simple Membership [simple-membership] < 4.0.9 Cross-Site Request Forgery (CSRF) Medium 4.7 < 4.0.9 4.0.9 2022-01-25

CVE-2022-0328

The Simple Membership plugin versions prior to 4.0.9 lack proper cross-site request forgery protection during bulk member deletion operations, potentially enabling attackers to trick authenticated administrators into removing members without their knowledge or consent through a CSRF attack vector.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.