LiveActive security incident?Get immediate response
CVE Record

CVE-2017-2222: Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject a...

Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2017-2222 affects older WP-Members WordPress plugin versions. A remote attacker may inject script or HTML through unspecified inputs, causing malicious code to run in a visitor’s browser. The sources do not provide CVSS scoring, exploit details, or evidence of active exploitation.

Executive priority

Treat this as a targeted maintenance item for WordPress membership sites. It is not documented as actively exploited here, but browser-side script injection can harm users and trust. Upgrade affected plugin versions promptly during normal security patch cycles.

Technical view

The CVE and JVN describe a cross-site scripting issue in WP-Members by Chad Butler before version 3.1.8. The vulnerable vectors are unspecified. Successful exploitation could allow arbitrary web script or HTML injection. No CWE, CVSS vector, or detailed trigger condition is included in the provided sources.

Likely exposure

Exposure is limited to WordPress sites running WP-Members prior to 3.1.8. Public membership, registration, login, or profile workflows may be relevant, but the exact affected input path is not specified in the source bundle.

Exploitation context

The sources state remote attackers can inject arbitrary web script or HTML. They do not state active exploitation, public weaponization, authentication requirements, or whether the issue is stored or reflected. KEV status is false in the provided bundle.

Researcher notes

The key limitation is missing vector detail. Researchers should avoid assuming affected parameters, authentication state, or persistence. Use the WordPress changeset and JVN advisory to understand the vendor-side fix, then validate defensively against authorized test instances only.

Mitigation direction

  • Upgrade WP-Members to version 3.1.8 or later.
  • Confirm the installed plugin came from the official WordPress plugin source.
  • Review JVN and WordPress plugin developer notes for vendor guidance.
  • Apply standard WordPress hardening and least-privilege admin practices.
  • Prioritize remediation for internet-facing membership sites.

Validation and detection

  • Inventory WordPress sites using the WP-Members plugin.
  • Verify each installed WP-Members version is 3.1.8 or later.
  • Check plugin changelog history around version 3.1.8.
  • Review web application test results for XSS handling in WP-Members workflows.
  • Confirm no vulnerable plugin copies remain in backups or staging sites.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-2222 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Chad ButlerWP-Membersprior to version 3.1.8Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.