← back
CVE-2024-5596

ARMember Premium <= 6.7 - Cross-Site Request Forgery via multiple functions

CVSS 6.3 MEDIUMEPSS 0.2%CWE-352
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Jun 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L