PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-0885

9.8
CVSS
Description

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

Attack Vector
-
Privileges Req.
-
User Interaction
-
member hero
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE history: member hero

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →