Security readout for executives and security teams
Plain-English summary
CVE-2017-2222 affects older WP-Members WordPress plugin versions. A remote attacker may inject script or HTML through unspecified inputs, causing malicious code to run in a visitor’s browser. The sources do not provide CVSS scoring, exploit details, or evidence of active exploitation.
Executive priority
Treat this as a targeted maintenance item for WordPress membership sites. It is not documented as actively exploited here, but browser-side script injection can harm users and trust. Upgrade affected plugin versions promptly during normal security patch cycles.
Technical view
The CVE and JVN describe a cross-site scripting issue in WP-Members by Chad Butler before version 3.1.8. The vulnerable vectors are unspecified. Successful exploitation could allow arbitrary web script or HTML injection. No CWE, CVSS vector, or detailed trigger condition is included in the provided sources.
Likely exposure
Exposure is limited to WordPress sites running WP-Members prior to 3.1.8. Public membership, registration, login, or profile workflows may be relevant, but the exact affected input path is not specified in the source bundle.
Exploitation context
The sources state remote attackers can inject arbitrary web script or HTML. They do not state active exploitation, public weaponization, authentication requirements, or whether the issue is stored or reflected. KEV status is false in the provided bundle.
Researcher notes
The key limitation is missing vector detail. Researchers should avoid assuming affected parameters, authentication state, or persistence. Use the WordPress changeset and JVN advisory to understand the vendor-side fix, then validate defensively against authorized test instances only.
Mitigation direction
- Upgrade WP-Members to version 3.1.8 or later.
- Confirm the installed plugin came from the official WordPress plugin source.
- Review JVN and WordPress plugin developer notes for vendor guidance.
- Apply standard WordPress hardening and least-privilege admin practices.
- Prioritize remediation for internet-facing membership sites.
Validation and detection
- Inventory WordPress sites using the WP-Members plugin.
- Verify each installed WP-Members version is 3.1.8 or later.
- Check plugin changelog history around version 3.1.8.
- Review web application test results for XSS handling in WP-Members workflows.
- Confirm no vulnerable plugin copies remain in backups or staging sites.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-2222 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://wordpress.org/plugins/wp-members/#developersCVE reference · x_refsource_CONFIRM
- JVN#51355647CVE reference · third-party-advisory, x_refsource_JVN
- https://plugins.trac.wordpress.org/changeset/1667369/#file12CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
