Skip to content

Known CVE

WCFM Membership <= 2.10.0 - Broken Access Control

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.

CVE-2022-4940

High2022CVSS 7.3CWE-862

cve2022 · wordpress · wp-scan · wp-plugin · wcfm · vkev · woocommerce

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website