What the vulnerability does
01Description
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
What the vulnerability does
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
Explanation of Vulnerability in Simple Terms
Ultimate Membership Pro versions 12.7 and earlier contain an authentication bypass vulnerability. An attacker can bypass login mechanisms without valid credentials, gaining unauthorized access to user accounts and administrative functions. The vulnerability affects confidentiality, integrity, and availability of the site. Update to a version newer than 12.7 immediately.
What an attacker can do
Bypass login authentication and gain unauthorized access to user accounts and site administration.
Potential impact on your site
Attackers can access member accounts, modify site data, and potentially take over the site without knowing passwords.
Conditions required to exploit
Network access only; no authentication, user interaction, or special configuration required.
Key dates
External resources
Related vulnerabilities