The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:18:06.636Z
Reserved: 2024-06-03T12:57:51.027Z
Link: CVE-2024-5596

Updated: 2024-08-01T21:18:06.636Z

Status : Awaiting Analysis
Published: 2024-06-22T06:15:11.470
Modified: 2024-11-21T09:47:59.330
Link: CVE-2024-5596

No data.