CVE · High

CVE-2022-2273 — Simple Membership [simple-membership] < 4.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2273 Simple Membership [simple-membership] < 4.1.3 Improper Privilege Management High 8.8 < 4.1.3 4.1.3 2022-07-06

CVE-2022-2273

The Simple Membership plugin for WordPress through version 4.1.2 contains a privilege escalation vulnerability affecting membership functionality. Authenticated users can exploit inadequate validation of the membership_level parameter to assign themselves arbitrary membership levels, thereby gaining unintended permissions. The vulnerability was patched in version 4.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.