Memberhero operates a membership and community management platform, with its vulnerability footprint concentrated in the core Member Hero product. The recurring security signals center on code injection and authorization control weaknesses, which are characteristic of web application frameworks handling dynamic content and access policies. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Memberhero over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0885CRITICAL The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call a | Jun 13, 2022 | 9.8 | 40 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Memberhero.
Media articles that mention a CVE ID that affects a product developed by Memberhero — matched by CVE ID, not by vendor name.