First published: Fri Nov 01 2024(Updated: )
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paid Memberships Pro | <3.0.5 | |
Paid Memberships Pro | <=3.0.4 | |
Paid Memberships Pro | <=3.0.4 |
Update to 3.0.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37277 is classified as a high severity vulnerability due to its potential for unauthorized access.
To fix CVE-2024-37277, upgrade Paid Memberships Pro to version 3.0.5 or higher.
CVE-2024-37277 allows unauthorized users to bypass access controls and access restricted functionality.
CVE-2024-37277 affects all versions of Paid Memberships Pro up to and including 3.0.4.
CVE-2024-37277 is specific to the Paid Memberships Pro plugin, which may be used in many WordPress sites.