Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4940

Опубликовано: 05 апр. 2023
Источник: nvd
CVSS3: 7.3
CVSS3: 6.5
EPSS Средний

Описание

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wclovers:wcfm_membership:*:*:*:*:*:wordpress:*:*
Версия до 2.10.11 (исключая)

EPSS

Процентиль: 94%
0.15335
Средний

7.3 High

CVSS3

6.5 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 6.5
github
почти 3 года назад

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.

EPSS

Процентиль: 94%
0.15335
Средний

7.3 High

CVSS3

6.5 Medium

CVSS3

Дефекты