8.8
CVSSv3

CVE-2019-14328

Published: 28/07/2019 Updated: 05/08/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Simple Membership plugin prior to 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

simple-membership-plugin simple membership

Exploits

# Exploit Title: Cross Site Request Forgery in Wordpress Simple Membership plugin # Date: 2019-07-27 # Exploit Author: rubyman # Vendor Homepage: wordpressorg/plugins/simple-membership/ # wpvulndb : wpvulndbcom/vulnerabilities/9482 # Version: 384 # Tested on: Windows 81 # CVE : CVE-2019-14328 # # Change localhost to your desir ...
WordPress Simple Membership plugin version 384 suffers from a cross site request forgery vulnerability ...