Vulnerabilities > Armemberplugin > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-12 CVE-2023-3011 Unspecified vulnerability in Armemberplugin Armember
The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5.
network
low complexity
armemberplugin
8.8
2022-12-06 CVE-2022-42888 Improper Privilege Management vulnerability in Armemberplugin Armember
Unauth.
network
low complexity
armemberplugin CWE-269
8.8
2022-06-27 CVE-2022-1903 Unspecified vulnerability in Armemberplugin Armember
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
network
high complexity
armemberplugin
8.1