Record summary

CVE-2024-0624 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC.

Description

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 25, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

Browse strangerstudios / Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions

Default status: unaffected

CVE ListThrough 2.12.7affected

Proofs of concept

1

Repository PoCs

GitHubkodaichodai/CVE-2024-0624Repository PoCby kodaichodaiStars: 0Not analyzed1 file

546 B

GitHub

PoC details

References

4