CVE-2017-1002008: Membership Simplified Project Membership Simplified

Critical severity, CVSS 9.8. EPSS: 16.9% chance of exploitation in the next 30 days.

Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

Affected products

Published 2017-09-14. Last modified 2026-06-17.