Description
WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.10.1 or latest
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2000-1206)
WordPress Plugin Minimal Coming Soon & Maintenance Mode-Coming Soon Page Security Bypass (2.15)
WordPress Plugin Asgaros Forum Security Bypass (1.5.7)
WordPress Plugin WP Banners Lite Cross-Site Scripting (1.40)
WordPress Plugin Slideshow Gallery LITE Multiple Unspecified Vulnerabilities (1.5.3.3)