Vulnerabilities > CVE-2023-6855 - Missing Authorization vulnerability in Strangerstudios Paid Memberships PRO

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
strangerstudios
CWE-862

Summary

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.

Vulnerable Configurations

Part Description Count
Application
Strangerstudios
269

Common Weakness Enumeration (CWE)