CVE-2022-4940 affects the WCFM Membership plugin for WordPress, versions up to and including 2.10.0. It is a broken access control vulnerability allowing unauthenticated attackers to modify membership details, change renewal information, and control approvals due to missing capability checks on AJAX actions. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low complexity, leading to data confidentiality and integrity impacts. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates for this high-severity vulnerability are available. Community discussion and media coverage are minimal, which is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.11CPE matchmatch criteria | cpe:2.3:a:wclovers:wcfm_membership:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.