Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Armemberplugin Subscribe
Filtered by product Armember
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-42888 1 Armemberplugin 1 Armember 2022-12-12 N/A 8.8 HIGH
Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
CVE-2022-1903 1 Armemberplugin 1 Armember 2022-07-06 6.8 MEDIUM 8.1 HIGH
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username