CVE-2022-4940
WCFM Membership <= 2.10.0 - Missing Authorization
Record summary
CVE-2022-4940 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.
Description
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 6, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WCFM Membership – WooCommerce Memberships for Multivendor MarketplaceBrowse wclovers / WCFM Membership – WooCommerce Memberships for Multivendor MarketplaceDefault status: unaffected | CVE List | Through 2.10.0 | affected |
wcfm_membershipBrowse wclovers / wcfm_membership | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWCFM Membership <= 2.10.0 - Broken Access ControlCVSS 7.3
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.
Impact
Unauthenticated attackers can modify membership details, approve or deny memberships, and change renewal info, potentially leading to data tampering and unauthorized access.
Remediation
Update to WCFM Membership version 2.10.1 or later.
Source: ProjectDiscovery