CVE Database /
CVE-2024-49682
CVE · Medium
CVE-2024-49682 — Simple Membership [simple-membership] < 4.5.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-49682
|
Simple Membership [simple-membership] < 4.5.4 |
URL Redirection to Untrusted Site ('Open Redirect') |
Medium
4.7
|
< 4.5.4
|
4.5.4 |
2024-10-21 |
—
|
CVE-2024-49682
The Simple Membership plugin contains an open redirect vulnerability affecting versions 4.5.3 and earlier because the plugin fails to adequately validate redirect URLs. An unauthenticated attacker could exploit this flaw to redirect users to external malicious websites, provided the attacker can deceive users into clicking a crafted link. The vulnerability was resolved in version 4.5.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings