First published: Thu Jan 02 2025(Updated: )
Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Repute Infosystems ARMember – Membership Plugin | <=5.9.2 | |
WordPress ARMember | <=5.9.2 |
Update the WordPress ARMember Premium plugin to the latest available version (at least 5.9.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39994 is classified as a missing authorization vulnerability affecting ARMember Premium.
To fix CVE-2023-39994, update ARMember Premium to version 5.9.3 or later.
Exploiting CVE-2023-39994 may allow unauthorized access to sensitive user data due to incorrectly configured access controls.
CVE-2023-39994 affects all users of ARMember Premium version 5.9.2 and earlier.
As of now, the best workaround for CVE-2023-39994 is to upgrade the plugin to the latest version.