Description
WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.10.1 or latest
References
Related Vulnerabilities
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Cross-Site Request Forgery (2.7.2)
WordPress Plugin Zendesk Help Center by BestWebSoft Cross-Site Scripting (1.0.4)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.1)
UAParser.js Inefficient Regular Expression Complexity Vulnerability (CVE-2022-25927)