CVE-2024-0624 — Cross-Site Request Forgery in Paid Memberships PRO
Severity
5.3MEDIUMNVD
EPSS
4.0%
top 11.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 25
Latest updateApr 11
Description
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages1 packages
Patches
🔴Vulnerability Details
3VulDB▶
Paid Memberships Pro Plugin up to 2.12.7 on WordPress Level Orders Update cross-site request forgery (ID 3025164)↗2026-04-11
CVEList
▶
GHSA▶
GHSA-47g8-q2w5-x9jm: The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forge↗2024-01-25