Cross-Site Request Forgery Vulnerability in Paid Memberships Pro Plugin
CVE-2024-3215
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 2 May 2024
Summary
The Paid Memberships Pro plugin for WordPress, which facilitates content restriction and user registration, contains a vulnerability due to improper nonce validation in the pmpro_update_level_group_order() function. This allows unauthenticated attackers to exploit the inadequacy by tricking site administrators into executing unwanted actions. Specifically, by crafting a forged request, attackers could manipulate order levels on affected sites, compromising the security and integrity of user content and subscriptions.
Affected Version(s)
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions * <= 3.0.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Whit Taylor