CVE-2022-4939
Summary
| CVE | CVE-2022-4939 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-05 19:15:00 UTC |
| Updated | 2023-11-07 03:59:00 UTC |
| Description | THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the membership registration form in a way that allows them to set the role for registration to that of any user including administrators. Once configured, the attacker can then register as an administrator. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.