Stored Cross-Site Scripting Vulnerability in ARMember Membership Plugin
CVE-2024-7703
Summary
The ARMember Membership Plugin for WordPress has a vulnerability that enables stored cross-site scripting through improperly handled SVG file uploads. This issue arises from inadequate input sanitization and output escaping mechanisms, allowing authenticated users with Subscriber-level access or higher to inject malicious web scripts. When these SVG files are accessed by other users, the embedded scripts are executed in their browsers, potentially leading to unauthorized actions or data exposure. It is crucial for users of affected versions to apply security updates and review their configurations to mitigate this risk.
Affected Version(s)
ARMember β Membership Plugin, Content Restriction, Member Levels, User Profile & User signup * <= 4.0.37
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved