Stored Cross-Site Scripting Vulnerability in ARMember Membership Plugin
CVE-2024-7703

6.4MEDIUM

Key Information:

Badges

πŸ‘Ύ Exploit Exists

Summary

The ARMember Membership Plugin for WordPress has a vulnerability that enables stored cross-site scripting through improperly handled SVG file uploads. This issue arises from inadequate input sanitization and output escaping mechanisms, allowing authenticated users with Subscriber-level access or higher to inject malicious web scripts. When these SVG files are accessed by other users, the embedded scripts are executed in their browsers, potentially leading to unauthorized actions or data exposure. It is crucial for users of affected versions to apply security updates and review their configurations to mitigate this risk.

Affected Version(s)

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup * <= 4.0.37

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.