What the vulnerability does
01Description
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
Explanation of Vulnerability in Simple Terms
Paid Memberships Pro versions up to 1.2.3 lack proper authorization checks, allowing authenticated users to modify site data they should not have access to. An attacker with a low-privilege account can alter or delete content belonging to other users or the site itself. The vulnerability requires an existing user account but no additional user interaction.
What an attacker can do
Modify or delete site data and other users' content without proper authorization.
Potential impact on your site
Unauthorized users can alter or delete critical site content, membership data, or other users' information.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities