Show filters
22 Total Results
Displaying 21-22 of 22
Sort by:
Attacker Value
Unknown

CVE-2022-42888

Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
Attacker Value
Unknown

CVE-2022-1903

Disclosure Date: June 27, 2022 (last updated October 07, 2023)
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username