CVE-2019-14328: CSRF
Published Jul 28, 2019
·Updated
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
Affected Software
1 affected component
Simple-membership-plugin Simple Membership Wordpress<3.8.5
Event History
Jul 28, 2019
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14328?
CVE-2019-14328 has a medium severity level due to the potential for CSRF attacks.
2
How do I fix CVE-2019-14328?
To fix CVE-2019-14328, update the Simple Membership plugin to version 3.8.5 or later.
3
What is the impact of CVE-2019-14328?
CVE-2019-14328 can allow an attacker to perform unauthorized bulk operations within the Simple Membership plugin.
4
Which versions of the Simple Membership plugin are affected by CVE-2019-14328?
CVE-2019-14328 affects all versions of the Simple Membership plugin prior to 3.8.5.
5
Are there any workarounds for CVE-2019-14328?
Currently, the best workaround for CVE-2019-14328 is to manually disable the Bulk Operation section until the plugin is updated.