First published: Wed Apr 24 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.11.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paid Memberships Pro | <=2.11.0 | |
Paid Membership Subscriptions | <=2.11.0 |
Update to 2.11.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32728 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2024-32728, update the Paid Member Subscriptions plugin to version 2.11.1 or later.
CVE-2024-32728 affects Paid Member Subscriptions versions from n/a up to and including 2.11.0.
Yes, CVE-2024-32728 is exploitable by an attacker to perform unauthorized actions on behalf of an authenticated user.
Users of the Paid Member Subscriptions plugin for WordPress versions 2.11.0 and earlier are affected by CVE-2024-32728.