Description
WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to change user passwords and potentially take over administrator accounts. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.11.0 or latest
References
https://lana.codes/lanavdb/3a841453-d083-4f97-a7f1-b398c7304284/
https://plugins.svn.wordpress.org/wc-multivendor-membership/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin BadgeOS SQL Injection (3.7.1.2)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.27)
Oracle Database Server CVE-2014-6545 Vulnerability (CVE-2014-6545)
Joomla! Core 1.0.x Unspecified Vulnerability (1.0.0 - 1.0.3)
WordPress Plugin TeraWallet-For WooCommerce Insecure Direct Object Reference (1.4.3)