The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.
References
Configurations
History
21 Nov 2024, 07:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/wp-members/trunk/includes/admin/tabs/class-wp-members-admin-tab-fields.php?rev=2895180#L799 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/2920897/wp-members/trunk/includes/admin/tabs/class-wp-members-admin-tab-fields.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/bf05a79a-0375-4c9d-bbf0-a87484327b87?source=cve - Third Party Advisory |
28 Oct 2024, 11:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:butlerblog:wp-members:*:*:*:*:*:wordpress:*:* | |
First Time |
Butlerblog
Butlerblog wp-members |
07 Nov 2023, 04:13
Type | Values Removed | Values Added |
---|---|---|
CWE |
19 Jul 2023, 13:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:wp-members_project:wp-members:*:*:*:*:*:wordpress:*:* | |
First Time |
Wp-members Project
Wp-members Project wp-members |
|
References | (MISC) https://plugins.trac.wordpress.org/browser/wp-members/trunk/includes/admin/tabs/class-wp-members-admin-tab-fields.php?rev=2895180#L799 - Product | |
References | (MISC) https://plugins.trac.wordpress.org/changeset/2920897/wp-members/trunk/includes/admin/tabs/class-wp-members-admin-tab-fields.php - Patch | |
References | (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/bf05a79a-0375-4c9d-bbf0-a87484327b87?source=cve - Third Party Advisory |
12 Jul 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-12 05:15
Updated : 2024-11-21 07:59
NVD link : CVE-2023-2869
Mitre link : CVE-2023-2869
CVE.ORG link : CVE-2023-2869
JSON object : View
Products Affected
butlerblog
- wp-members
CWE
No CWE.