PT-2023-11894 · WordPress · Paid Memberships Pro

Jerome Bruandet

·

Published

2023-10-20

·

Updated

2023-12-28

·

CVE-2020-36754

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Paid Memberships Pro plugin for WordPress versions up to, and including, 2.4.2
Description The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the pmpro page save() function. This allows unauthenticated attackers to save pages via a forged request if they can trick a site administrator into performing an action, such as clicking on a link.
Recommendations For versions up to, and including, 2.4.2, consider disabling the pmpro page save() function until a patch is available to prevent exploitation. Restrict access to sensitive pages and ensure that site administrators are cautious when clicking on links from untrusted sources. Update to a version later than 2.4.2 when available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-36754

Affected Products

Paid Memberships Pro