What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.
Explanation of Vulnerability in Simple Terms
WishList Member X before version 3.26.7 contains a code injection vulnerability that allows authenticated users with low privileges to run arbitrary PHP code on the site. The vulnerability affects the scope beyond the vulnerable component, meaning an attacker can compromise the entire site. All versions before 3.26.7 are affected.
What an attacker can do
Run arbitrary PHP code on the site with full control over data and functionality.
Potential impact on your site
Complete site compromise: attackers can steal data, modify content, create admin accounts, or take the site offline.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or member role).
Key dates
External resources
Related vulnerabilities