CVE-2017-1002008
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
14/09/2017
Last modified:
20/04/2025
Description
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:membership_simplified_project:membership_simplified:1.58:*:*:*:*:wordpress:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.vapidlabs.com/advisory.php?v=187
- https://wordpress.org/plugins/membership-simplified-for-oap-members-only
- https://wpvulndb.com/vulnerabilities/8777
- https://www.exploit-db.com/exploits/41622/
- http://www.vapidlabs.com/advisory.php?v=187
- https://wordpress.org/plugins/membership-simplified-for-oap-members-only
- https://wpvulndb.com/vulnerabilities/8777
- https://www.exploit-db.com/exploits/41622/



