CVE-2024-0969
ARMember <= 4.0.24 - Improper Access Control to Sensitive Information Exposure via REST API
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restriction" feature and view restricted post content.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
reputeinfosystems · ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →