Impact
The YourMembership Single Sign On – YM SSO Login plugin contains a missing capability check in the moym_display_test_attributes function. This allows any unauthenticated user to invoke the function and read the profile data of the most recent SSO login, resulting in sensitive user information being disclosed without authorization.
Affected Systems
Affected software is the WordPress plugin Login with YourMembership – YM SSO Login from vendor cyberlord92. All releases up to and including version 1.1.7 are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score of < 1% suggests low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request targeting the moym_display_test_attributes endpoint; the attacker needs no credentials and can simply craft a request to retrieve the sensitive data.
OpenCVE Enrichment