CVE-2023-2869: Butlerblog Wp-Members
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.
Affected products
- Butlerblog Wp-Members: before 3.4.8 (fixed in 3.4.8)
Published 2023-07-12. Last modified 2026-06-17.