Medium severity6.5NVD Advisory· Published Mar 21, 2022· Updated Jun 17, 2026
CVE-2022-0681
CVE-2022-0681
Description
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <4.1.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/c5765816-4439-4c14-a847-044248ada0efnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.