CVE-2023-2276

CVSS V2 None CVSS V3 None
Description
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.
Overview
  • CVE ID
  • CVE-2023-2276
  • Assigner
  • security@wordfence.com
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-20T04:15:09
  • Last Modified Date
  • 2023-05-20T04:15:09
History
Created Old Value New Value Data Type Notes
2023-05-20 05:00:22 Added to TrackCVE
2023-05-20 05:00:23 Weakness Enumeration new