CVE-2023-6855: Paid Memberships Pro <= 2.12.5 - Missing Authorization via API
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmprorestapigetpermissionscheck function in all versions up to 2.12.5 (inclusive). This makes it possible for unauthenticated attackers to change membership levels including prices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6855?
CVE-2023-6855 has a medium severity level due to its potential for unauthorized modification of membership levels.
How do I fix CVE-2023-6855?
To fix CVE-2023-6855, update the Paid Memberships Pro plugin to version 2.12.6 or later.
What are the potential impacts of CVE-2023-6855?
The potential impacts of CVE-2023-6855 include unauthorized access to modify membership levels, which could compromise user data.
Which versions of Paid Memberships Pro are affected by CVE-2023-6855?
CVE-2023-6855 affects Paid Memberships Pro versions up to and including 2.12.5.
What specific function is responsible for the vulnerability in CVE-2023-6855?
The vulnerability in CVE-2023-6855 is due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function.