The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.
id: CVE-2022-4940
info:
name: WCFM Membership <= 2.10.0 - Broken Access Control
author: 0xanis
...