Indeed Membership Pro <= 12.7 - Unauthenticated Privilege Escalation
2024-08-12 00:00
Rafie MuhammadStrategic Overview
StatusPatched in 12.8
Affected PluginIndeed Membership Pro
Affected Version
<= 12.7CVSS9.8Critical
CVE
CVE-2024-43240Vulnerability Overview
The Indeed Membership Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 12.7. This is due to the plugin not properly restricting access to functionality that allows privilege assignment. This makes it possible for unauthenticated attackers to gain access to accounts that have higher privileges, such as administrator.
Technical Analysis
REMEDIATION: Update to version 12.8, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C