CVE-2024-22308: WordPress Simple Membership Plugin <= 4.4.1 is vulnerable to Open Redirection
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wp.Insider Simple Membershipto a version that resolves this vulnerability.Fixed in 4.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22308?
CVE-2024-22308 is classified as a medium severity vulnerability due to its potential for exploitation through open redirection.
How do I fix CVE-2024-22308?
To fix CVE-2024-22308, update the Simple Membership plugin to version 4.4.2 or later.
What systems are affected by CVE-2024-22308?
CVE-2024-22308 affects Simple Membership plugin versions from n/a through 4.4.1.
What kind of vulnerability is CVE-2024-22308?
CVE-2024-22308 is an open redirect vulnerability that may lead users to untrusted sites.
Who is impacted by CVE-2024-22308?
Users of the Simple Membership plugin on WordPress who have not updated to version 4.4.2 are impacted by CVE-2024-22308.