CVE-2015-4038

Wpmembership - Access Control

Title source: rule

Description

The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/37074

Scores

EPSS 0.1197
EPSS Percentile 93.8%

Details

CWE
CWE-264
Status published
Products (1)
wpmembership/wpmembership 1.2.3
Published Jun 03, 2015
Tracked Since Feb 18, 2026