CVE-2024-7703: ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.37 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7703?
CVE-2024-7703 is rated as a high severity vulnerability due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2024-7703?
To fix CVE-2024-7703, update the ARMember Membership Plugin to the latest version beyond 4.0.37, which addresses the input sanitization issue.
Who is affected by CVE-2024-7703?
CVE-2024-7703 affects all versions of the ARMember Membership Plugin for WordPress up to and including 4.0.37.
What type of vulnerability is CVE-2024-7703?
CVE-2024-7703 is a stored cross-site scripting vulnerability arising from insufficient input validation of SVG file uploads.
What can attackers do with CVE-2024-7703?
Attackers exploiting CVE-2024-7703 can execute arbitrary JavaScript in the context of a user's session, potentially compromising user data and site security.