ProfilePress Membership Team ProfilePress Vulnerable to Missing Authorization
CVE-2023-41953
5.3MEDIUM
Summary
A vulnerability has been identified in the ProfilePress Membership plugin that allows unauthorized access to certain functionalities. This flaw stems from inadequate authorization checks, which can lead to unauthorized users gaining access to sensitive member data and capabilities within the software. Specifically, versions from n/a through 4.13.1 are impacted, leaving them susceptible to potential exploitation if not promptly addressed.
Affected Version(s)
ProfilePress <= 4.13.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)