Vulnerabilities > CVE-2022-0885 - Missing Authorization vulnerability in Memberhero Member Hero 1.0.9

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
memberhero
CWE-862
critical

Summary

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

Vulnerable Configurations

Part Description Count
Application
Memberhero
2

Common Weakness Enumeration (CWE)