Simple Membership < 4.1.3 - Unauthenticated Membership Privilege Escalation
CVE-2022-2317
9.8CRITICAL
What is CVE-2022-2317?
The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.
Affected Version(s)
Simple Membership 4.1.3