CVE-2024-37277 HIGH

CVE-2024-37277: WordPress Paid Memberships Pro plugin <= 3.0.4 - Insecure Direct Object References (IDOR) vulnerability

Vendor Paid Memberships Pro
Product Paid Memberships Pro
Weakness CWE-639 · IDOR
Published November 1, 2024
Last update April 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

Explanation of Vulnerability in Simple Terms

02Summary

Paid Memberships Pro versions up to 3.0.4 contain an authorization bypass vulnerability that allows unauthenticated attackers to modify membership data and settings. The vulnerability stems from insufficient access controls on critical administrative functions. An attacker can exploit this over the network without requiring user interaction, potentially compromising membership records and site configuration.

What an attacker can do

03Attacker Capabilities

Modify membership data, settings, and user records without authentication.

Potential impact on your site

04Site Impact

Membership records, pricing, and site settings can be altered by unauthorized parties.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

November 1, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE