cleantalk
Vulnerabilities and Security Researches

Simple Membership, CVE-2022-2273

CVE, Research URL

CVE-2022-2273

Application

Simple Membership

Published on
Aug 01, 2022
Research Description
The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.
Affected versions
max 4.1.3.
Status
vulnerable