Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18850
HistoryMar 02, 2022 - 12:00 a.m.

WordPress Simple Membership plugin跨站请求伪造漏洞

2022-03-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
12

0.001 Low

EPSS

Percentile

30.0%

WordPress is a set of blogging platforms developed by the WordPress Foundation using the PHP language. A cross-site request forgery vulnerability exists in versions of the WordPress Simple Membership plugin prior to 4.0.9. The vulnerability stems from the fact that the Simple Membership plugin does not have CSRF checks when deleting members in bulk, and an attacker could exploit this vulnerability to by launching a CSRF attack.

0.001 Low

EPSS

Percentile

30.0%