Vulnerabilities > Wclovers > Wcfm Membership > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-05-20 CVE-2023-2276 Authorization Bypass Through User-Controlled Key vulnerability in Wclovers Wcfm Membership
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7.
network
low complexity
wclovers CWE-639
critical
9.8
2023-04-05 CVE-2022-4939 Unspecified vulnerability in Wclovers Wcfm Membership
THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings.
network
low complexity
wclovers
critical
9.8