6.5
CVSSv2

CVE-2015-4038

Published: 03/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpmembership wpmembership 1.2.3

Exploits

# Exploit Title: WordPress WP Membership plugin [Multiple Vulnerabilities] # Date: 2015/05/19 # Exploit Author: Panagiotis Vagenas # Contact: twittercom/panVagenas # Vendor Homepage: wpmembershipe-pluginscom/ # Software Link: codecanyonnet/item/wp-membership/10066554 # Version: 123 # Tested on: WordPress 422 # Category ...