← WordPress Vulnerabilities
WordPress security by component

WCFM Membership

WCFM Membership is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Apr 05, 2023; the highest CVE/CNA score is 9.8.

Plugin slug: wcfm-membership

CVE-2022-4941: WCFM Membership: Cross-site request forgery

WCFM Membership is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedApr 05, 2023
Safe version guidanceSee mitigation notes
Safe version
Apr 05, 2023 CVE-2022-4941
WCFM Membership: Cross-site request forgery
WCFM Membership is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.3
NVD8.8
Apr 05, 2023 CVE-2022-4940
WCFM Membership: A security weakness
WCFM Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD6.5
Apr 05, 2023 CVE-2022-4939
WCFM Membership: Privilege escalation or authentication bypass
WCFM Membership is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8