VYPR
Unrated severityNVD Advisory· Published Jun 3, 2015· Updated May 6, 2026

CVE-2015-4038

CVE-2015-4038

Description

The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.