What the vulnerability does
01Description
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
What the vulnerability does
Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.
Explanation of Vulnerability in Simple Terms
Simple Membership versions up to 4.3.4 contain a privilege management flaw that allows unauthenticated attackers to modify user roles and permissions. The vulnerability requires no user interaction and can be exploited over the network. An attacker can escalate their own account or demote administrators, compromising site access control.
What an attacker can do
Change user roles and permissions without authentication, including promoting themselves to admin.
Potential impact on your site
Attackers can take over admin accounts or create new administrators, gaining full control of your site.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities