CVE-2023-4719
- EPSS 1.42%
- Veröffentlicht 06.09.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:49
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, una...
CVE-2022-4469
- EPSS 0.25%
- Veröffentlicht 16.01.2023 16:15:12
- Zuletzt bearbeitet 08.04.2025 20:15:18
The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scriptin...
CVE-2022-2317
- EPSS 0.9%
- Veröffentlicht 01.08.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:00:45
The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.
CVE-2022-2273
- EPSS 0.68%
- Veröffentlicht 01.08.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:39
The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.
CVE-2022-1724
- EPSS 5.22%
- Veröffentlicht 13.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 06:41:19
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
CVE-2022-0681
- EPSS 0.14%
- Veröffentlicht 21.03.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:39:10
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
CVE-2022-0328
- EPSS 0.11%
- Veröffentlicht 28.02.2022 09:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:23
The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
CVE-2016-10884
- EPSS 0.3%
- Veröffentlicht 14.08.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 02:44:59
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
CVE-2017-18499
- EPSS 0.23%
- Veröffentlicht 12.08.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 03:20:15
The simple-membership plugin before 3.5.7 for WordPress has XSS.
CVE-2019-14328
- EPSS 0.47%
- Veröffentlicht 28.07.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:26:30
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.