Unrated severityNVD Advisory· Published Jun 3, 2015· Updated May 6, 2026
CVE-2015-4038
CVE-2015-4038
Description
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.
Affected products
1- cpe:2.3:a:wpmembership:wpmembership:1.2.3:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.