WordPress ARMember Plugin <= 4.0.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-47140
7.1HIGH
What is CVE-2022-47140?
The ARMember plugin for WordPress is vulnerable to an unauthenticated reflected cross-site scripting (XSS) attack, allowing attackers to inject malicious scripts through user inputs. This vulnerability affects versions equal to or lower than 4.0.1, enabling exploitation without user authentication, potentially compromising the security of the site's users and data.
Affected Version(s)
ARMember <= 4.0.1