Impact
The Simple Membership plugin for WordPress contains a missing authorization check in versions 4.8.2 and earlier. This flaw can allow an unauthenticated or minimally privileged user to invoke privileged plugin functions that should be restricted to administrators or designated members. The result could be unauthorized reading or modification of membership data, potentially exposing sensitive user information or altering membership status without consent.
Affected Systems
WordPress sites running the Simple Membership plugin version 4.8.2 or older are affected. The plugin is distributed by wp.insider. No additional vendor or product variants are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is via the plugin’s exposed functionality in the WordPress administration interface. Because the flaw is an access control issue rather than an injection or remote execution bug, the exploit requires knowledge of the plugin’s operations but does not demand elevated privileges beyond the public web interface.
OpenCVE Enrichment