Indeed Membership Pro <= 7.5 - Remote Image File Inclusion

2019-02-26 00:00
James Fraser

Strategic Overview

Status
Patched in 7.6
Affected PluginIndeed Membership Pro
Affected Version<= 7.5
CVSS8.3High
CVEN/A
View all Indeed Membership Pro vulnerabilities

Vulnerability Overview

The Indeed Membership Pro plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 7.5 via the imgUrl feature. This allows unauthorized attackers to include remote files on the server, resulting in code execution.

Technical Analysis

REMEDIATION: Update to version 7.6, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C