Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6855

Опубликовано: 11 янв. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*
Версия до 2.12.5 (включая)

EPSS

Процентиль: 57%
0.00347
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 5.3
github
около 2 лет назад

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.

EPSS

Процентиль: 57%
0.00347
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862
CWE-862