Impact
A stored cross‑site scripting flaw in the country field exposes it to injection of arbitrary scripts. When an authenticated user with subscriber‑level or higher privileges submits a malicious payload, the text is stored and rendered without proper sanitization, causing the script to execute in any browser that visits the page. The vulnerability thus permits privilege‑escalated script execution that could steal or manipulate session data and compromise confidentiality and integrity of user interactions. Even users with anonymous front‑end registration can exploit the flaw if the free membership feature is enabled, broadening the potential impact to unauthenticated users.
Affected Systems
The flaw affects the Simple Membership WordPress plugin for all releases up to and including 4.8.4. End‑users running any of these versions on their WordPress sites are vulnerable; the issue is resolved in 4.8.5 and later.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity while the EPSS score is not available, suggesting limited information about active exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is authenticated subscriber‑level access, though unauthenticated exploitation is possible when the free membership option is enabled. An attacker would need to submit a malicious value for the country field via the member form, after which the script would run in the browsers of any visitor to the affected pages.
OpenCVE Enrichment