CVE-2024-12919

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 287

Summary

CVE-2024-12919 is a critical vulnerability affecting the Paid Membership Subscriptions plugin for WordPress. In versions 2.13.7 and below, the plugin's pms_pb_payment_redirect_link function allows unauthenticated attackers to bypass authentication. By supplying a user-controlled payment ID, attackers can authenticate as any user who has made a purchase on the targeted site without undergoing any further identity validation. This puts user accounts and sensitive data at risk. It's essential for WordPress users to update to the latest version of the plugin or consider using alternative plugins to secure their sites.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share