Vulnerabilities > Membership Simplified Project

DATE CVE VULNERABILITY TITLE RISK
2017-09-14 CVE-2017-1002008 Unrestricted Upload of File with Dangerous Type vulnerability in Membership Simplified Project Membership Simplified 1.58
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
network
low complexity
membership-simplified-project CWE-434
critical
9.8