CVE-2024-12919: Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pmspbpaymentredirectlink function using the user-controlled value supplied via the 'pmspaymentid' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12919?
CVE-2024-12919 has a high severity due to the authentication bypass vulnerability that can allow unauthorized access.
How do I fix CVE-2024-12919?
To fix CVE-2024-12919, update the Paid Membership Subscriptions plugin to version 2.13.8 or later.
What versions of the plugin are affected by CVE-2024-12919?
All versions of the Paid Membership Subscriptions plugin up to and including 2.13.7 are affected by CVE-2024-12919.
Can CVE-2024-12919 lead to data breaches?
Yes, CVE-2024-12919 can potentially lead to data breaches due to unauthorized access to restricted content.
Who is the vendor of the software vulnerable to CVE-2024-12919?
The vendor of the software affected by CVE-2024-12919 is Cozmoslabs, associated with the Effortless Memberships plugin.