CVE-2016-10884: CSRF
Published Aug 14, 2019
·Updated
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
Affected Software
1 affected component
Simple-membership-plugin Simple Membership Wordpress<3.3.3
Event History
Aug 14, 2019
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10884?
CVE-2016-10884 is classified as a medium severity vulnerability due to its potential for CSRF exploitation.
2
How do I fix CVE-2016-10884?
To fix CVE-2016-10884, upgrade the Simple Membership plugin to version 3.3.3 or later.
3
What systems are affected by CVE-2016-10884?
CVE-2016-10884 affects WordPress sites using the Simple Membership plugin versions prior to 3.3.3.
4
What type of vulnerability is CVE-2016-10884?
CVE-2016-10884 involves multiple Cross-Site Request Forgery (CSRF) vulnerabilities.
5
Can CVE-2016-10884 lead to user account compromise?
Yes, if exploited, CVE-2016-10884 can potentially allow an attacker to perform unauthorized actions on behalf of users.