Record summary

CVE-2022-1903 has a selected CVSS score of 8.1 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 6, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE List3.4.8 to < 3.4.8affected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubbiulove0x/CVE-2022-1903Repository PoCby biulove0xStars: 1Not analyzed3 files

4.9 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHARMember < 3.4.8 - Unauthenticated Admin Account TakeoverCVSS 8.1

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username.

Impact

An attacker can gain unauthorized access to the admin account, potentially leading to further compromise of the system.

Remediation

Fixed in version 3.4.8

WeaknessesCWE-862
Authorstheamanrawat
Template tagscvecve2022account-takeoverwpscanwordpresswp-pluginwparmember-membershipunauthenticatedarmemberpluginvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:armemberplugin:armember:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2