What the vulnerability does
01Description
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
Explanation of Vulnerability in Simple Terms
Simple Membership versions up to 4.3.4 contain an authentication bypass vulnerability. An attacker with low-level user privileges can gain unauthorized access to sensitive data and modify site content. The vulnerability stems from improper authentication checks that fail to properly validate user credentials or session state.
What an attacker can do
Read sensitive data, modify site content, and perform administrative actions without proper authorization.
Potential impact on your site
Compromised user accounts can access restricted content, modify posts/pages, and escalate privileges within the membership system.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities