Impact
This vulnerability is a Missing Authorization flaw that allows an attacker to bypass access controls within the WP Membership plugin. By exploiting incorrectly configured security levels, an attacker can access content or perform actions that should be restricted to privileged users. The impact is a potential compromise of confidentiality and integrity of protected membership data.
Affected Systems
The problem exists in the WP Membership plugin from e-plugins, specifically versions up to and including 1.6.4. All WordPress sites that depend on these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 7.3 places this flaw in the high category, while the EPSS score of less than 1% suggests that exploitation is currently infrequent but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web-based, with an attacker submitting crafted requests to the plugin’s admin endpoints to gain unauthorized access.
OpenCVE Enrichment