Impact
The vulnerability in the WCFM Membership plugin is an insecure direct object reference that allows an authenticated user with vendor level or higher access to change another user’s role to 'wcfm_vendor' by manipulating the membership plan via the 'wcfmvm_membership_change' AJAX action escalation (CWE‑639) because the attacker can bestow vendor privileges on an arbitrary account without the description detailing the specific capabilities of the 'wcfm_vendor' role, but providing that role is recognized as an escalation of privileges.
Affected Systems
WordPress installations that use the WCFM Membership – WooCommerce Membership plugin10 marketplace with the plugin deployed in one of these releases must verify their current plugin version.
Risk and Exploitability
The flaw has a CVSS score of 8.1, indicating high severity. The EPSS score of < 1% suggests a very low probability of exploitation at present, and the vulnerability has not been listed in the CISA KEV catalog. Based on the description, the attack vector requires an authenticated user with vendor-level or higher privileges; the attacker manipulates the AJAX action to overwrite user roles. Successful exploitation allows the attacker to assume vendor‑level privileges, which is a limited privilege escalation.
OpenCVE Enrichment