What the vulnerability does
01Description
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.
Explanation of Vulnerability in Simple Terms
MemberPress versions up to 1.11.34 lack proper authorization checks, allowing unauthenticated attackers to read and modify sensitive data. An attacker can access restricted content and user information without logging in. The vulnerability affects confidentiality and integrity but not availability. Update to a version newer than 1.11.34 to resolve this issue.
What an attacker can do
Read and modify restricted user data and content without authentication.
Potential impact on your site
Unauthorized users can access member-only content, view private data, and potentially alter site information.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities