armemberplugin Vulnerabilities and Affected Products
Vulnerabilities associated with armember.
Products
Clear product- armember3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-47837HIGH | WordPress ARMember plugin <= 4.0.10 - Membership Plan Bypass vulnerabilityImproper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10. CWE-269Jun 4, 2024 | CVSS8.3v3.1 | EPSS0.386% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32948CRITICAL | WordPress ARMember – Membership Plugin plugin <= 4.0.28 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28. CWE-862Apr 24, 2024 | CVSS9.1v3.1 | EPSS0.568% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1903HIGH | ARMember < 3.4.8 - Unauthenticated Admin Account TakeoverThe ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username | CVSS8.1v3.1 | EPSS8.59% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |