Vulnerabilities > Imember360

DATE CVE VULNERABILITY TITLE RISK
2014-11-16 CVE-2014-8949 Code Injection vulnerability in Imember360
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter.
network
imember360 CWE-94
6.0
2014-11-16 CVE-2014-8948 Cross-Site Request Forgery (CSRF) vulnerability in Imember360
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter.
6.8
2014-05-23 CVE-2014-3849 Permissions, Privileges, and Access Controls vulnerability in Imember360
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.
4.3
2014-05-23 CVE-2014-3848 Permissions, Privileges, and Access Controls vulnerability in Imember360
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
network
low complexity
imember360 CWE-264
5.0
2014-05-22 CVE-2014-3842 Cross-Site Scripting vulnerability in Imember360
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.
network
imember360 CWE-79
4.3