CVE-2023-41957: WordPress Simple Membership plugin <= 4.3.4 - Unauthenticated Membership Role Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
Affected Software
2 affected components
WordPress Simple Membership<=4.3.4
Simple-membership-plugin Simple Membership Wordpress<4.3.5
Remediation
Information
Update to 4.3.5 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
May 29, 57201
Event
via NVD·02:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-41957?
CVE-2023-41957 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2023-41957?
To fix CVE-2023-41957, update the Simple Membership plugin to version 4.3.5 or later.
3
What versions are affected by CVE-2023-41957?
CVE-2023-41957 affects versions of Simple Membership from earlier than 4.3.5 up to and including 4.3.4.
4
What are the implications of CVE-2023-41957?
CVE-2023-41957 allows unauthorized users to gain elevated privileges within the Simple Membership plugin.
5
Who is impacted by CVE-2023-41957?
Users of the Simple Membership plugin on WordPress running versions up to 4.3.4 are impacted by CVE-2023-41957.