vendor:
Simple Membership
by:
rubyman
8.8
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: Simple Membership
Affected Version From: 3.8.2004
Affected Version To: 3.8.2004
Patch Exists: NO
Related CWE: CVE-2019-14328
CPE: a:simple_membership_project:simple_membership:3.8.4
Platforms Tested: Windows 8.1
2019
Cross Site Request Forgery in WordPress Simple Membership plugin
This exploit allows an attacker to perform unauthorized actions on behalf of a user by tricking them into submitting a malicious form. In this case, the exploit targets the WordPress Simple Membership plugin, allowing the attacker to change a user's membership level.
Mitigation:
The vendor should release a patch to fix this vulnerability. Users should update to the latest version of the plugin and ensure they have proper security measures in place to protect against CSRF attacks.