CVE-2024-37277: WordPress Paid Memberships Pro plugin <= 3.0.4 - Insecure Direct Object References (IDOR) vulnerability
Published Nov 1, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
Affected Software
3 affected components
Strangerstudios Paid Memberships Pro Wordpress<3.0.5
Paid Memberships Pro Paid Memberships Pro<=3.0.4
WordPress Paid Memberships Pro<=3.0.4
Remediation
Information
Update to 3.0.5 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37277?
CVE-2024-37277 is classified as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-37277?
To fix CVE-2024-37277, upgrade Paid Memberships Pro to version 3.0.5 or higher.
3
What are the impacts of CVE-2024-37277?
CVE-2024-37277 allows unauthorized users to bypass access controls and access restricted functionality.
4
Which versions of Paid Memberships Pro are affected by CVE-2024-37277?
CVE-2024-37277 affects all versions of Paid Memberships Pro up to and including 3.0.4.
5
Is CVE-2024-37277 a common vulnerability in WordPress?
CVE-2024-37277 is specific to the Paid Memberships Pro plugin, which may be used in many WordPress sites.