CVE-2022-0885
Member Hero <= 1.0.9 - Unauthenticated RCE
Record summary
CVE-2022-0885 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Member HeroDefault status: affected | CVE List | Through 1.0.9 | affected |
member_heroBrowse memberhero / member_hero | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALMember Hero <=1.0.9 - Remote Code ExecutionCVSS 9.8
WordPress Member Hero plugin through 1.0.9 is susceptible to remote code execution. The plugin lacks authorization checks and does not validate the a request parameter in an AJAX action, allowing an attacker to call arbitrary PHP functions with no arguments. An attacker can thus execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Impact
An attacker can execute arbitrary code on the target system, potentially leading to a complete compromise of the WordPress site.
Remediation
Update to the latest version of the Member Hero plugin (1.0.9 or higher) to mitigate this vulnerability.
Source: ProjectDiscovery