Access Control Flaw in iMember360 Plugin for WordPress
CVE-2014-3848
Currently unrated
What is CVE-2014-3848?
The iMember360 plugin for WordPress exhibits a significant access control flaw in versions prior to 3.9.001. This vulnerability allows remote attackers to exploit the i4w_dbinfo parameter, gaining unauthorized access to sensitive database credentials. By bypassing established access restrictions, attackers can retrieve critical information, potentially leading to further exploitation of the WordPress environment.