The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-59059 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-06-03T14:09:46.500Z

Reserved: 2023-12-15T17:01:59.388Z

Link: CVE-2023-6855

cve-icon Vulnrichment

Updated: 2024-08-02T08:42:08.250Z

cve-icon NVD

Status : Modified

Published: 2024-01-11T09:15:52.613

Modified: 2025-06-03T14:15:41.083

Link: CVE-2023-6855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.