Impact
Based on the description, it is inferred that the vulnerability is a missing authorization flaw that allows access to functionality that should be protected by access control lists. An attacker could exploit this flaw to trigger privileged actions such as modifying membership records, changing user roles, or accessing confidential member information. The weakness is categorized as a broken access control (CWE‑862).
Affected Systems
Any WordPress site that has the Memberful Membership Plugin installed at version 1.75.0 or earlier. No other versions are stated to be affected, but the vulnerability is present throughout the specified version range.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests that exploit attempts are infrequent. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely exploitation would involve sending crafted HTTP requests to the plugin’s endpoints; an authenticated user or one who can obtain valid credentials could potentially bypass role restrictions. While exploitation is technically possible, the low EPSS score indicates a small likelihood of successful attacks against this vulnerability at present.
OpenCVE Enrichment
EUVD