Lucene search

K
cvelistWPScanCVELIST:CVE-2022-2273
HistoryAug 01, 2022 - 12:51 p.m.

CVE-2022-2273 Simple Membership < 4.1.3 - Membership Privilege Escalation

2022-08-0112:51:22
CWE-269
WPScan
www.cve.org
1
simple membership
wordpress
privilege escalation
cve-2022-2273
validation
profile editing

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

42.9%

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.

CNA Affected

[
  {
    "product": "Simple Membership",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "4.1.3",
        "status": "affected",
        "version": "4.1.3",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

42.9%