CVE-2024-5596
ARMember Premium <= 6.7 - Cross-Site Request Forgery via multiple functions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation.
El complemento ARMember Premium para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 6.7 incluida. Esto se debe a una función de validación nonce implementada incorrectamente en múltiples funciones. Esto hace posible que atacantes no autenticados modifiquen o eliminen metaopciones y complementos del usuario, lo que puede conducir a una escalada de privilegios limitada.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-06-03 CVE Reserved
- 2024-06-21 CVE Published
- 2024-08-01 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Armember Search vendor "Armember" | ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User Signup Search vendor "Armember" for product "ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User Signup" | <= 6.7 Search vendor "Armember" for product "ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User Signup" and version " <= 6.7" | en |
Affected
|