Impact
The Joomla extension Membership Pro prior to version 4.6.2 allows unauthenticated users to upload media assets by default. This flaw permits an attacker to upload any media file, which can then be accessed by other users or processed by the server, potentially affecting the site’s integrity. The vulnerability is a classic example of insecure default configuration (CWE-1188) that permits unauthorized access to a critical function.
Affected Systems
The affected product is the Membership Pro extension for Joomla by joomdonation.com. All installations running a version prior to 4.6.2 are impacted and need to be evaluated for this default configuration.
Risk and Exploitability
The CVSS score of 9.1 classifies this as Critical, and the EPSS score of less than 1% indicates that while exploitation opportunities are currently low, the high severity warrants immediate action. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this vulnerability by simply uploading a file from any unauthenticated session, assuming the server accepts or serves the uploaded content without proper validation.
OpenCVE Enrichment