CVE-2022-1903: ARMember < 3.4.8 - Unauthenticated Admin Account Takeover
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1903?
CVE-2022-1903 is a vulnerability in the ARMember WordPress plugin before 3.4.8 that allows unauthenticated users to change the password of arbitrary users by knowing their username.
What is the severity of CVE-2022-1903?
CVE-2022-1903 has a severity rating of 8.1 (High).
How does CVE-2022-1903 affect ARMember WordPress plugin?
CVE-2022-1903 affects the ARMember WordPress plugin before version 3.4.8.
Is there a fix available for CVE-2022-1903?
Yes, updating the ARMember WordPress plugin to version 3.4.8 or later will fix the vulnerability.
Where can I find more information about CVE-2022-1903?
More information about CVE-2022-1903 can be found at the following reference link: [CVE-2022-1903](https://wpscan.com/vulnerability/28d26aa6-a8db-4c20-9ec7-39821c606a08).