Cross-Site Request Forgery in Paid Memberships Pro Plugin for WordPress
CVE-2020-36754
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 20 October 2023
What is CVE-2020-36754?
The Paid Memberships Pro plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to improper nonce validation within the pmpro_page_save() function. An unauthenticated attacker could exploit this vulnerability by tricking an administrator into clicking a malicious link, thereby manipulating page data without authorization. This raises significant security concerns for systems utilizing this plugin, especially in scenarios where user permissions are not strictly managed.
Affected Version(s)
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions * < 2.4.3