s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 - Information Exposure
2024-03-18 00:00
Francesco CarlucciStrategic Overview
StatusPatched in 240315
Affected Plugins2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
Affected Version
<= 230815CVSS5.3Medium
CVE
CVE-2024-0899Vulnerability Overview
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of those posts and pages.
Technical Analysis
REMEDIATION: Update to version 240315, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C