CVE-2023-41956: WordPress Simple Membership plugin <= 4.3.4 - Authenticated Account Takeover vulnerability
Published May 17, 2024
·Updated
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
Affected Software
2 affected components
WordPress Simple Membership<=4.3.4
Simple-membership-plugin Simple Membership Wordpress<4.3.5
Remediation
Information
Update to 4.3.5 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:55 AM
Data Sourced
via MITRE·06:55 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41956?
CVE-2023-41956 is classified as a high severity improper authentication vulnerability.
2
How do I fix CVE-2023-41956?
To fix CVE-2023-41956, update the Simple Membership plugin to version 4.3.5 or later.
3
What versions are affected by CVE-2023-41956?
CVE-2023-41956 affects all versions of Simple Membership from n/a to 4.3.4 inclusive.
4
What impact does CVE-2023-41956 have on users?
CVE-2023-41956 allows authenticated users to potentially take over accounts due to improper authentication checks.
5
Is there a patch available for CVE-2023-41956?
Yes, a patch is available in version 4.3.5 of the Simple Membership plugin.