CVE-2023-40608: WordPress Paid Memberships Pro CCBill Gateway plugin <= 0.3 - Unauthenticated Broken Access Control vulnerability
Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40608?
CVE-2023-40608 is classified as a missing authorization vulnerability which poses a significant risk to user data and access control.
How do I fix CVE-2023-40608?
To fix CVE-2023-40608, update the Paid Memberships Pro CCBill Gateway plugin to a version beyond 0.3.
What versions are affected by CVE-2023-40608?
CVE-2023-40608 affects the Paid Memberships Pro CCBill Gateway plugin versions up to and including 0.3.
What impact does CVE-2023-40608 have?
CVE-2023-40608 can potentially allow unauthorized users to access and manipulate membership-related functionalities.
Is there a workaround for CVE-2023-40608?
A temporary workaround for CVE-2023-40608 is to disable the Paid Memberships Pro CCBill Gateway plugin until it can be updated.