// For flags

CVE-2022-2273

Simple Membership < 4.1.3 - Membership Privilege Escalation

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.

El plugin Simple Membership de WordPress versiones anteriores a 4.1.3, no comprueba correctamente el parámetro membership_level cuando se edita un perfil, lo que permite a los miembros escalar a un nivel de membresía superior usando una petición POST diseñada

The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, and including, 4.1.2. This is due to insufficient validation on the membership membership_level supplied which makes it possible for authenticated users to supplied arbitrary membership levels and be granted to permissions.

*Credits: Jet Infosystems
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-06-30 CVE Reserved
  • 2022-07-06 CVE Published
  • 2024-02-22 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Simple-membership-plugin
Search vendor "Simple-membership-plugin"
Simple Membership
Search vendor "Simple-membership-plugin" for product "Simple Membership"
< 4.1.3
Search vendor "Simple-membership-plugin" for product "Simple Membership" and version " < 4.1.3"
wordpress
Affected