Cross-Site Request Forgery Vulnerability in Paid Memberships Pro Plugin
CVE-2024-3215
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 2 May 2024
What is CVE-2024-3215?
The Paid Memberships Pro plugin for WordPress, which facilitates content restriction and user registration, contains a vulnerability due to improper nonce validation in the pmpro_update_level_group_order() function. This allows unauthenticated attackers to exploit the inadequacy by tricking site administrators into executing unwanted actions. Specifically, by crafting a forged request, attackers could manipulate order levels on affected sites, compromising the security and integrity of user content and subscriptions.
Affected Version(s)
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions * <= 3.0.1