CSRF Vulnerabilities in Simple Membership Plugin for WordPress
CVE-2016-10884
8.8HIGH
Summary
The Simple Membership Plugin for WordPress, prior to version 3.3.3, has exposed multiple Cross-Site Request Forgery (CSRF) vulnerabilities. These issues could allow an attacker to trick users into inadvertently executing unwanted actions on their behalf within the application. As a result, attackers could potentially manipulate user accounts, affecting both site functionality and user privacy.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved