Description
WordPress Plugin Paid Memberships Pro-Content Restriction, User Registration, & Paid Subscriptions is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to update an order status to paid. WordPress Plugin Paid Memberships Pro-Content Restriction, User Registration, & Paid Subscriptions version 3.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.5 or latest
References
Related Vulnerabilities
WordPress Plugin Abandoned Cart Pro for WooCommerce Cross-Site Scripting (7.11.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5341)
OpenSSL Other Vulnerability (CVE-2015-3194)
e107 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3731)