CVE · Critical

CVE-2022-2317 — Simple Membership [simple-membership] < 4.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2317 Simple Membership [simple-membership] < 4.1.3 Improper Privilege Management Critical 9.8 < 4.1.3 4.1.3 2022-07-06

CVE-2022-2317

The Simple Membership plugin for WordPress before version 4.1.3 contains a privilege escalation vulnerability where membership level identifiers lack proper validation. An unauthenticated attacker can exploit this flaw by submitting arbitrary membership levels, allowing them to gain unauthorized permissions and escalate their privileges within the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.