CVE-2024-0624Cross-Site Request Forgery in Paid Memberships PRO

Severity
5.3MEDIUMNVD
EPSS
4.0%
top 11.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 25
Latest updateApr 11

Description

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
VulDB
Paid Memberships Pro Plugin up to 2.12.7 on WordPress Level Orders Update cross-site request forgery (ID 3025164)2026-04-11
CVEList
Paid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Update2024-01-25
GHSA
GHSA-47g8-q2w5-x9jm: The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forge2024-01-25
CVE-2024-0624 — Cross-Site Request Forgery | cvebase