Lucene search

K
nessusThis script is Copyright (C) 2023-2024 and is owned by Tenable, Inc. or an Affiliate thereof.WEB_APPLICATION_SCANNING_114052
HistoryOct 05, 2023 - 12:00 a.m.

Simple Membership Plugin For WordPress < 4.1.3 Multiple Vulnerabilities

2023-10-0500:00:00
This script is Copyright (C) 2023-2024 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
4
wordpress
simple membership plugin
vulnerabilities
privilege escalation
validation

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.8%

The WordPress Simple Member Plugin installed on the remote host is affected by multiple vulnerabilities as follows:

  • A privilege escalation flaw due to insufficient validation on the membership level_identifier supplied, which permits unauthenticated attackers to supply arbitrary membership levels and be granted these permissions (CVE-2022-2317). - A privilege escalation flaw due to insufficient validation on the membership membership_level supplied, which permits authenticated attackers to supply arbitrary membership levels and be granted these permissions (CVE-2022-2273).

Note that the scanner has not tested for these issues but has instead relied only on the application’s self-reported version number.

No source data
VendorProductVersionCPE
simple-membership-pluginsimple_membership*cpe:2.3:a:simple-membership-plugin:simple_membership:*:*:*:*:*:wordpress:*:*

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.8%

Related for WEB_APPLICATION_SCANNING_114052