CVE-2024-12287

CRITICAL

Biagiotti Membership <1.0.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, such as administrators, granted they have access to an email.

Scores

CVSS v3 9.8
EPSS 0.0055
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
Mikado-Themes/Biagiotti Membership < 1.0.2
Published Dec 18, 2024
Tracked Since Feb 18, 2026