CVE · Medium

CVE-2022-0681 — Simple Membership [simple-membership] < 4.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0681 Simple Membership [simple-membership] < 4.1.0 Cross-Site Request Forgery (CSRF) Medium 6.5 < 4.1.0 4.1.0 2022-02-25

CVE-2022-0681

The Simple Membership plugin versions prior to 4.1.0 lacks adequate CSRF safeguards when handling transaction deletions. This vulnerability permits attackers to craft malicious requests that trick authenticated administrators into removing transactions without their knowledge or consent. An attacker could exploit this flaw by having an admin visit a compromised web page while logged into WordPress, resulting in unwanted transaction removal. Upgrading to version 4.1.0 or later resolves this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.