Impact
The vulnerability in WP Membership plugin allows an attacker with a lower privilege level to obtain higher-level permissions by exploiting incorrect privilege assignment. An unauthorized user could gain administrative capabilities, enabling further attacks such as modifying site content, installing malware, or accessing sensitive data.
Affected Systems
WordPress sites running the e-plugins WP Membership plugin version 1.6.4 or earlier are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is below 1%, suggesting low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through the web-based administration interface; an attacker would need at least a user account, but can elevate privileges without additional authentication steps. Exploitation requires no additional conditions beyond the presence of the vulnerable plugin.
OpenCVE Enrichment