CVE-2014-3849
published 2014-05-23CVE-2014-3849: The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a…
PriorityP339medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
5.97%
92.4th percentile
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| imember360 | imember360 | — | — |
| imember360 | imember360 | — | — |
| imember360 | imember360 | — | — |
| imember360 | imember360 | — | — |
| imember360 | imember360 | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2014/Apr/265http://www.exploit-db.com/exploits/33076http://www.osvdb.org/106300http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2014/Apr/265http://www.exploit-db.com/exploits/33076http://www.osvdb.org/106300
2014-05-23
Published