CVE-2023-2869: WP-Members Membership <= 3.4.7.3 - Missing Authorization to Settings Update
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the dofieldreorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-2869?
CVE-2023-2869 is a vulnerability in the WP-Members Membership plugin for WordPress that allows authenticated attackers with subscriber-level access to unauthorizedly update plugin settings.
How severe is CVE-2023-2869?
CVE-2023-2869 has a severity level of medium.
Which version of WP-Members Membership plugin is affected by CVE-2023-2869?
Versions up to, and including, 3.4.7.3 of the WP-Members Membership plugin are affected by CVE-2023-2869.
How can an attacker exploit CVE-2023-2869?
Authenticated attackers with subscriber-level access can exploit CVE-2023-2869 to reorder plugin settings.
Are there any references related to CVE-2023-2869?
Yes, you can find references related to CVE-2023-2869 here: [Reference 1](https://plugins.trac.wordpress.org/browser/wp-members/trunk/includes/admin/tabs/class-wp-members-admin-tab-fields.php?rev=2895180#L799), [Reference 2](https://plugins.trac.wordpress.org/changeset/2920897/wp-members/trunk/includes/admin/tabs/class-wp-members-admin-tab-fields.php), [Reference 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/bf05a79a-0375-4c9d-bbf0-a87484327b87?source=cve).