The Paid Memberships Pro – Content Restriction, User...
Moderate severity
Unreviewed
Published
Apr 9, 2024
to the GitHub Advisory Database
•
Updated Jan 17, 2025
Description
Published by the National Vulnerability Database
Apr 9, 2024
Published to the GitHub Advisory Database
Apr 9, 2024
Last updated
Jan 17, 2025
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible for unauthenticated attackers to enable the streamline setting with Lifter LMS via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
References