The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46781 | The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:18:06.636Z
Reserved: 2024-06-03T12:57:51.027Z
Link: CVE-2024-5596
Updated: 2024-08-01T21:18:06.636Z
Status : Awaiting Analysis
Published: 2024-06-22T06:15:11.470
Modified: 2024-11-21T09:47:59.330
Link: CVE-2024-5596
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:49Z
Weaknesses
No weakness.
EUVD