Unrated severityNVD Advisory· Published Jun 13, 2022· Updated Aug 2, 2024
Member Hero <= 1.0.9 - Unauthenticated RCE
CVE-2022-0885
Description
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/8b08b72e-5584-4f25-ab73-5ab0f47412dfmitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.