Cross-Site Request Forgery in Paid Memberships Pro Plugin for WordPress
CVE-2020-36754
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 20 October 2023
What is CVE-2020-36754?
The Paid Memberships Pro plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to improper nonce validation within the pmpro_page_save() function. An unauthenticated attacker could exploit this vulnerability by tricking an administrator into clicking a malicious link, thereby manipulating page data without authorization. This raises significant security concerns for systems utilizing this plugin, especially in scenarios where user permissions are not strictly managed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Paid Memberships Pro β Content Restriction, User Registration, & Paid Subscriptions * < 2.4.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved