PT-2022-14181 · WordPress · Armember

Cydave

·

Published

2022-06-27

·

Updated

2022-07-06

·

CVE-2022-1903

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ARMember WordPress plugin versions prior to 3.4.8
Description The issue allows for account takeover, including administrator accounts, due to missing nonce and authorization checks in an AJAX action. This action is available to unauthenticated users, enabling them to change the password of any user by knowing their username.
Recommendations For versions prior to 3.4.8, update to version 3.4.8 or later to resolve the issue.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1903

Affected Products

Armember