← back
CVE-2022-2273CWE-269

Simple Membership < 4.1.3 - Membership Privilege Escalation

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing members to escalate to a higher membership level by using a crafted POST request.