CVE-2022-0328: Simple Membership < 4.0.9 - Arbitrary Member Deletion via CSRF
Published Feb 28, 2022
·Updated
The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
Affected Software
1 affected component
Simple-membership-plugin Simple Membership Wordpress<4.0.9
Event History
Feb 28, 2022
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0328?
CVE-2022-0328 is considered a high severity vulnerability due to the potential for unauthorized deletion of user accounts.
2
How do I fix CVE-2022-0328?
To fix CVE-2022-0328, update the Simple Membership WordPress plugin to version 4.0.9 or later.
3
Who is affected by CVE-2022-0328?
CVE-2022-0328 affects users of the Simple Membership WordPress plugin versions prior to 4.0.9.
4
What kind of attack does CVE-2022-0328 allow?
CVE-2022-0328 allows attackers to perform a cross-site request forgery (CSRF) attack to delete users in bulk.
5
Is there a known exploit for CVE-2022-0328?
As of now, there are no publicly available exploits specifically for CVE-2022-0328, but the vulnerability is still a significant risk.