Description
WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to change user passwords and potentially take over administrator accounts. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.11.0 or latest
References
https://lana.codes/lanavdb/3a841453-d083-4f97-a7f1-b398c7304284/
https://plugins.svn.wordpress.org/wc-multivendor-membership/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WP Attachment Export Arbitrary File Download (0.2.3)
WordPress Plugin WP Insightly for Contact Form 7 and Ninja Forms Cross-Site Scripting (1.0.7)
Oracle JRE CVE-2013-2432 Vulnerability (CVE-2013-2432)
WebLogic Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-40690)
WordPress Plugin YaMaps for WordPress Cross-Site Scripting (0.6.25)