Impact
A vulnerability in the WordPress Simple Membership plugin up to version 4.7.8 allows unauthenticated users to bypass access controls and gain unauthorized access to protected functionality. This flaw corresponds to CWE-862, where a lack of proper authorization checks permits users to perform actions they should not be allowed to do. The available description indicates that no authentication is required to trigger the exploit, meaning any visitor could potentially abuse the broken controls.
Affected Systems
WordPress sites running the Simple Membership plugin from the wp.insider vendor, specifically affected versions up to and including 4.7.8. Any deployment that has not yet updated beyond 4.7.8 is vulnerable and potentially exposes restricted features or data to unauthenticated actors.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity, suggesting significant risk to confidentiality and integrity. The EPSS score is not available, but the lack of a listed exploit in the KEV catalog indicates no confirmed public exploitation yet. However, the vulnerability can be leveraged via the web interface, with no prerequisites beyond a web request, making it potentially easy to exploit for anyone with internet access to the target site.
OpenCVE Enrichment