Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions <= 2.5.2 - IDOR to Sensitive Information Disclosure
Strategic Overview
< 2.5.3N/AVulnerability Overview
The Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions plugin for WordPress is vulnerable to sensitive information disclosure due to incorrect user validation and capabiltiy checking on the pmpro_get_order_json() function that made it possible for attackers to download order data for other users in versions up to, and including 2.5.2.
Technical Analysis
REMEDIATION: Update to version 2.5.3, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C