PT-2024-16456 · WordPress · Armember

Arkadiusz Hydzik

·

Published

2024-12-06

·

Updated

2024-12-06

·

CVE-2024-10681

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress versions up to, and including, 4.0.51
Description The issue is related to arbitrary shortcode execution due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.
Recommendations For versions up to, and including, 4.0.51, update to a version higher than 4.0.51 to resolve the issue. As a temporary workaround, consider restricting access to authenticated attackers with subscriber-level access and above to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-10681

Affected Products

Armember