s2Member <= 240315 - Limited Privilege Escalation
2024-04-05 00:00
Ngô Thiên An (ancorn_)Strategic Overview
StatusPatched in 240325
Affected Plugins2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
Affected Version
<= 240315CVSS9.1Critical
CVE
CVE-2024-31237Vulnerability Overview
The s2Member plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 240315. This is due to insufficient controls during user registration. This makes it possible for unauthenticated attackers to register with higher than the default permissions.
Technical Analysis
REMEDIATION: Update to version 240325, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C