Vulnerability Details CVE-2014-3849
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.11
EPSS Ranking 93.1%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-3849
-
cpe:2.3:a:imember360:imember360:3.8.012
-
cpe:2.3:a:imember360:imember360:3.8.013
-
cpe:2.3:a:imember360:imember360:3.8.014
-
cpe:2.3:a:imember360:imember360:3.9.000
-
cpe:2.3:a:imember360:imember360:3.9.001