First published: Fri Mar 08 2024(Updated: )
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP-Members Membership Plugin | <=3.4.9.1 | |
WordPress | <3.4.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1987 is considered a high severity vulnerability due to the potential for stored cross-site scripting attacks.
To fix CVE-2024-1987, update the WP-Members Membership Plugin to the latest version beyond 3.4.9.1 where the vulnerability is patched.
CVE-2024-1987 affects all versions of the WP-Members Membership Plugin for WordPress up to and including version 3.4.9.1.
Exploiting CVE-2024-1987 can allow an attacker to execute arbitrary JavaScript code in the context of an authenticated user's session.
CVE-2024-1987 was disclosed as a vulnerability in the WP-Members Membership Plugin for WordPress indicating a need for immediate attention.