CVE-2024-1390: Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via creating_pricing_table_page
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creatingpricingtablepage function in all versions up to, and including, 2.11.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create pricing tables.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1390?
CVE-2024-1390 is rated as a high severity vulnerability due to unauthorized modification of data.
How do I fix CVE-2024-1390?
To fix CVE-2024-1390, update the Paid Membership Subscriptions plugin to version 2.11.2 or higher.
Which versions are affected by CVE-2024-1390?
CVE-2024-1390 affects all versions of the Paid Membership Subscriptions plugin up to and including 2.11.1.
What is the cause of CVE-2024-1390?
CVE-2024-1390 is caused by a missing capability check in the creating_pricing_table_page function.
Who is affected by CVE-2024-1390?
WordPress users utilizing the Paid Membership Subscriptions plugin versions prior to 2.11.2 are affected by CVE-2024-1390.