Unsafe Shortcode Execution Vulnerability
CVE-2024-10681
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 6 December 2024
What is CVE-2024-10681?
The ARMember β Membership Plugin for WordPress has a significant vulnerability that allows malicious actors to execute arbitrary shortcodes. This issue arises from the plugin's failure to properly validate input values before processing the do_shortcode function. As a result, authenticated attackers with subscriber-level access or higher can exploit this flaw, potentially leading to unauthorized actions within the website. It's crucial for users of ARMember to address this vulnerability promptly to safeguard their sites against possible manipulation and misuse.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ARMember β Membership Plugin, Content Restriction, Member Levels, User Profile & User signup * <= 4.0.51
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved