CVE · Low

CVE-2024-22308 — Simple Membership [simple-membership] < 4.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-22308 Simple Membership [simple-membership] < 4.4.2 URL Redirection to Untrusted Site ('Open Redirect') Low 3.4 < 4.4.2 4.4.2 2024-01-19

CVE-2024-22308

The Simple Membership plugin before version 4.4.2 contains an open redirection flaw where user-supplied redirect URLs are not properly validated before being used. An attacker could exploit this vulnerability to redirect users from the legitimate site to a malicious destination, potentially facilitating phishing attacks or other social engineering schemes. The vulnerability was discovered by Joshua Chan and has been resolved in version 4.4.2 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.