Reflected Cross-Site Scripting Vulnerability in Simple Membership Plugin for WordPress
CVE-2023-4719
What is CVE-2023-4719?
The Simple Membership plugin for WordPress suffers from a Reflected Cross-Site Scripting vulnerability via the 'list_type' parameter. This flaw stems from inadequate input sanitization and output escaping in versions up to and including 4.3.5. Attackers could exploit this vulnerability to inject malicious scripts into web pages, potentially leading users to execute unintended actions if lured into clicking compromised links. It is essential for users and maintainers to ensure the plugin is updated to safeguard against such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Simple Membership * <= 4.3.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved