PT-2024-22802 · WordPress · Wp-Members Membership Plugin

Tim Coen

·

Published

2024-04-26

·

Updated

2024-04-26

·

CVE-2024-2920

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP-Members Membership Plugin versions up to, and including, 3.4.9.3
Description The issue allows unauthenticated attackers to view files uploaded by other users, which may contain sensitive information, due to the plugin uploading user-supplied files to a publicly accessible directory in wp-content without any restrictions.
Recommendations For versions up to, and including, 3.4.9.3, update to a version that fixes this issue to prevent information exposure. As a temporary workaround, consider restricting access to the wp-content directory to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-2920

Affected Products

Wp-Members Membership Plugin