CVE-2022-0328
Simple Membership < 4.0.9 - Arbitrary Member Deletion via CSRF
Severity Score
4.7
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
El plugin Simple Membership de WordPress versiones anteriores a 4.0.9, no presenta comprobación de tipo CSRF cuando son eliminados miembros en masa, lo que podría permitir a atacantes hacer que un administrador conectado los elimine por medio de un ataque de tipo CSRF
*Credits:
Krzysztof Zając
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-01-21 CVE Reserved
- 2022-01-25 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-10-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2662855 | Release Notes |
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/44532b7c-4d0d-4959-ada4-733f377d6ec9 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simple-membership-plugin Search vendor "Simple-membership-plugin" | Simple Membership Search vendor "Simple-membership-plugin" for product "Simple Membership" | < 4.0.9 Search vendor "Simple-membership-plugin" for product "Simple Membership" and version " < 4.0.9" | wordpress |
Affected
|