Showing 3 vulnerabilities on this page for armember

Signals CISA KEV Ransomware Nuclei
armemberplugin vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress ARMember plugin <= 4.0.10 - Membership Plan Bypass vulnerability

Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.

CWE-269Jun 4, 2024
CVSS8.3v3.1EPSS0.386%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WordPress ARMember – Membership Plugin plugin <= 4.0.28 - Broken Access Control vulnerability

Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.

CWE-862Apr 24, 2024
CVSS9.1v3.1EPSS0.568%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

CWE-862Jun 27, 20221 related artifact
CVSS8.1v3.1EPSS8.59%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX