CVE-2024-5596: ARMember Premium <= 6.7 - Cross-Site Request Forgery via multiple functions
The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5596?
CVE-2024-5596 has a high severity rating due to its potential for Cross-Site Request Forgery, which can allow unauthenticated attackers to perform unauthorized actions.
How do I fix CVE-2024-5596?
To fix CVE-2024-5596, update the ARMember Premium plugin to the latest version where the nonce validation vulnerabilities have been addressed.
Which versions are affected by CVE-2024-5596?
CVE-2024-5596 affects ARMember Premium plugin versions up to and including 6.7.
Can CVE-2024-5596 be exploited by authenticated users?
No, CVE-2024-5596 can be exploited by unauthenticated attackers due to improper nonce validation.
What type of vulnerability is CVE-2024-5596 classified as?
CVE-2024-5596 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.