CVE-2022-2273: Simple Membership < 4.1.3 - Membership Privilege Escalation
Published Aug 1, 2022
·Updated
The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membershiplevel parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.
Affected Software
1 affected component
Simple-membership-plugin Simple Membership Wordpress<4.1.3
Event History
Aug 1, 2022
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2273?
CVE-2022-2273 has a severity rating classified as medium due to its potential for membership level escalation.
2
How do I fix CVE-2022-2273?
To fix CVE-2022-2273, update the Simple Membership plugin to version 4.1.3 or later.
3
Who is affected by CVE-2022-2273?
CVE-2022-2273 affects users of the Simple Membership WordPress plugin prior to version 4.1.3.
4
What kind of attack does CVE-2022-2273 expose?
CVE-2022-2273 exposes users to a privilege escalation attack through the manipulation of the membership_level parameter.
5
What is the scope of CVE-2022-2273?
The vulnerability allows any member to gain unauthorized higher membership levels through a crafted POST request.