Impact
The MemberDash plugin for WordPress contains an insecure direct object reference that allows an unauthenticated attacker to supply an arbitrary user ID during registration and change the password for any user, including administrators, without the victim receiving any notification. This vulnerability permits full account takeover, giving the attacker complete control over the compromised accounts and the ability to perform any action permitted to that account. The weakness is a CWE‑639 type of reference error.
Affected Systems
All installations of the LearnDash MemberDash plugin up to and including version 1.8.5 are affected. The vulnerability is present in every release prior to 1.8.6 and affects systems running those versions on WordPress sites.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is classified as critical. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a simple HTTP POST request to the registration endpoint containing the 'id' parameter; no authentication is required. Because the flaw allows remote manipulation of user credentials, the exploitation effort is minimal and the impact is immediate, potentially allowing attackers to take over all privileged accounts on a site.
OpenCVE Enrichment