6.1
CVE-2024-4133
- EPSS 0.25%
- Veröffentlicht 02.05.2024 17:15:35
- Zuletzt bearbeitet 21.11.2024 09:42:15
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.30 - Open Redirect
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.30. This is due to insufficient validation on the redirect url supplied via the redirect_to parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Mögliche Gegenmaßnahme
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: Update to version 4.0.31, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Version
* - 4.0.30
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerreputeinfosystems
≫
Produkt
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Default Statusunaffected
Version <=
4.0.30
Version
*
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.484 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|