WordPress security by component
WCFM Membership
Plugin description
WCFM Membership is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Apr 05, 2023; the highest CVE/CNA score is 9.8.
Plugin slug:
wcfm-membershipLatest vulnerability
CVE-2022-4941: WCFM Membership: Cross-site request forgery
WCFM Membership is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
| Safe version |
|
||
|---|---|---|---|
| Apr 05, 2023 |
CVE-2022-4941
WCFM Membership: Cross-site request forgery
WCFM Membership is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.3
NVD8.8
|
| Apr 05, 2023 |
CVE-2022-4940
WCFM Membership: A security weakness
WCFM Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVD6.5
|
| Apr 05, 2023 |
CVE-2022-4939
WCFM Membership: Privilege escalation or authentication bypass
WCFM Membership is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVD9.8
|