vendor:
WP Membership
by:
Panagiotis Vagenas
7.5
CVSS
HIGH
Privilege escalation, Stored XSS, Unauthorized post publish and stored XSS
264, 79
CWE
Product Name: WP Membership
Affected Version From: 1.2.2003
Affected Version To: 1.2.2003
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress 4.2.2
2015
WordPress WP Membership plugin [Multiple Vulnerabilities]
Any registered user can perform a privilege escalation through `iv_membership_update_user_settings` AJAX action. Although this exploit can be used to modify other plugin related data (eg payment status and expiry date), privilege escalation can lead to a serious incident because the malicious user can take administrative role to the infected website. All input fields from registered users aren't properly escaped. This could lead to an XSS attack that could possibly affect all visitors of the website, including administators. Registered users can poublish posts without any authorization.
Mitigation:
No official solution yet exists.