CVE-2022-1903
ARMember < 3.4.8 - Unauthenticated Admin Account Takeover
Record summary
CVE-2022-1903 has a selected CVSS score of 8.1 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | CVE List | 3.4.8 to < 3.4.8 | affected |
armemberBrowse armemberplugin / armember | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubbiulove0x/CVE-2022-1903Repository PoCby biulove0xStars: 1Not analyzed3 files
Nuclei templates
1ProjectDiscoveryHIGHARMember < 3.4.8 - Unauthenticated Admin Account TakeoverCVSS 8.1
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username.
Impact
An attacker can gain unauthorized access to the admin account, potentially leading to further compromise of the system.
Remediation
Fixed in version 3.4.8
Source: ProjectDiscovery