CVE-2022-2317: Simple Membership < 4.1.3 - Unauthenticated Membership Privilege Escalation
Published Aug 1, 2022
·Updated
The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.
Affected Software
1 affected component
Simple-membership-plugin Simple Membership Wordpress<4.1.3
Event History
Aug 1, 2022
CVE Published
via MITRE·12:52 PM
Data Sourced
via MITRE·12:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2317?
CVE-2022-2317 has a moderate severity rating due to its potential for unauthorized membership changes.
2
How do I fix CVE-2022-2317?
To fix CVE-2022-2317, update the Simple Membership plugin to version 4.1.3 or later.
3
What systems are affected by CVE-2022-2317?
CVE-2022-2317 affects versions of the Simple Membership plugin prior to 4.1.3 installed on WordPress.
4
What exploit does CVE-2022-2317 allow?
CVE-2022-2317 allows users to change their membership level at the registration stage due to insufficient validation.
5
Is there a workaround for CVE-2022-2317?
There are no specific workarounds for CVE-2022-2317; updating the plugin is the recommended solution.