Record summary

CVE-2022-4940 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.

Description

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing renewal information, controlling membership approvals, and more.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 6, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

Browse wclovers / WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

Default status: unaffected

CVE ListThrough 2.10.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWCFM Membership <= 2.10.0 - Broken Access ControlCVSS 7.3

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.

Impact

Unauthenticated attackers can modify membership details, approve or deny memberships, and change renewal info, potentially leading to data tampering and unauthorized access.

Remediation

Update to WCFM Membership version 2.10.1 or later.

WeaknessesCWE-862
Authors0xanis
Template tagscvecve2022wordpresswp-scanwp-pluginwcfmvkevwoocommerce
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Shodan: http.html:"wc-multivendor-membership"
Google: inurl:"/wp-content/plugins/wc-multivendor-membership/"

Source: ProjectDiscovery

References

5