Vulnerabilities > Memberhero

DATE CVE VULNERABILITY TITLE RISK
2022-06-13 CVE-2022-0885 Missing Authorization vulnerability in Memberhero Member Hero 1.0.9
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
network
low complexity
memberhero CWE-862
critical
9.8