CVE-2022-0681
The Simple Membership plugin versions prior to 4.1.0 lacks adequate CSRF safeguards when handling transaction deletions. This vulnerability permits attackers to craft malicious requests that trick authenticated administrators into removing transactions without their knowledge or consent. An attacker could exploit this flaw by having an admin visit a compromised web page while logged into WordPress, resulting in unwanted transaction removal. Upgrading to version 4.1.0 or later resolves this security issue.
Based on public CVE data (MITRE/NVD).