ARMember <= 4.0.10 - Authenticated(Subscriber+) Privilege Escalation
2023-12-26 00:00
Revan ArifioStrategic Overview
StatusPatched in 4.0.11
Affected PluginARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Affected Version
<= 4.0.10CVSS8.8High
CVE
CVE-2023-51356Vulnerability Overview
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to privilege escalation due to insufficient input validation in all versions up to, and including, 4.0.10. This makes it possible for authenticated attackers, with subscriber access and above, to escalate their privileges.
Technical Analysis
REMEDIATION: Update to version 4.0.11, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C