Description
WordPress Plugin Simple Membership is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change addon settings. WordPress Plugin Simple Membership version 3.8.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.8.6 or latest
References
Related Vulnerabilities
WordPress 3.1.3 Multiple SQL Injection Vulnerabilities (3.1 - 3.1.3)
WordPress 'wp-register.php' Multiple Cross-Site Scripting Vulnerabilities (2.0 - 2.0.1)
Moodle URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-10133)
WordPress Plugin WP Page Widget Cross-Site Scripting (2.7)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-26071)