Critical severity9.8NVD Advisory· Published Sep 14, 2017· Updated May 13, 2026
CVE-2017-1002008
CVE-2017-1002008
Description
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
Affected products
2- cpe:2.3:a:membership_simplified_project:membership_simplified:1.58:*:*:*:*:wordpress:*:*
- William DeAngelis/membership-simplified-for-oap-members-onlyv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.vapidlabs.com/advisory.phpnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/41622/nvdExploitThird Party AdvisoryVDB Entry
- wpvulndb.com/vulnerabilities/8777nvdThird Party Advisory
- wordpress.org/plugins/membership-simplified-for-oap-members-onlynvdNot Applicable
News mentions
0No linked articles in our index yet.