CVE-2024-10537: WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validateusermetakey() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate user meta keys.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10537?
CVE-2024-10537 has a severity rating that indicates a potential risk of unauthorized access to user data.
How do I fix CVE-2024-10537?
To fix CVE-2024-10537, update the WP User Manager – User Profile Builder & Membership plugin to version 2.9.12 or later.
Who is affected by CVE-2024-10537?
CVE-2024-10537 affects all versions of the WP User Manager – User Profile Builder & Membership plugin up to and including 2.9.11.
What data is vulnerable in CVE-2024-10537?
CVE-2024-10537 allows unauthorized access to user metadata that should be restricted.
Is authentication required to exploit CVE-2024-10537?
Yes, CVE-2024-10537 requires an authenticated user to exploit the vulnerability.