S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-0885 Scanner

Detects 'Improper Access Control' vulnerability in Member Hero plugin for WordPress affects v. through 1.0.9.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0885
9.8
CVSS

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Member Hero
0
Updated Aug 19, 2026View on NVD →
Detail

The Member Hero plugin for WordPress is a tool used to help websites manage their memberships. With this plugin, users can create and sell different membership levels to access exclusive content or services on their website. Member Hero also allows website administrators to manage user accounts, track payments, and automate various membership-related tasks.

However, the Member Hero WordPress plugin through version 1.0.9 has been found to have a serious security vulnerability - CVE-2022-0885. This vulnerability occurs due to the lack of authorization checks and input validation in the code. Attackers can call arbitrary PHP functions with no arguments, even if they are not authenticated, opening a door to potential attacks.

Exploiting this vulnerability can result in several types of malicious activities, including account takeovers, data breaches, and denial-of-service attacks. Attackers can use this vulnerability to gain unauthorized access to user accounts, steal sensitive data, deploy malware, and cause substantial financial damages.

At s4e.io, we offer pro features that help website owners detect vulnerabilities in their digital assets quickly and easily. Our platform conducts vulnerability assessments, identifies security issues, and provides detailed reports for remediation. Protect your website from potential attacks by using our platform to enhance your security posture and safeguard your digital assets.

 

REFERENCES

Solution Advice

To prevent such attacks, website administrators should take the necessary precautions to protect their website from the exploitation of this vulnerability. Consider implementing the following measures:

  • Install the latest version of the Member Hero plugin, as it contains a fix for this vulnerability.
  • Ensure that all other WordPress plugins, themes, and core files are up-to-date.
  • Use strong passwords for all user accounts and encourage two-factor authentication.
  • Limit user permissions to only what is necessary and delete inactive user accounts.
  • Regularly monitor website activity, such as login attempts and file modifications, and use security plugins to detect possible attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.