CVE-2024-12919

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cozmoslabs:membership_\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:*

History

22 Jan 2025, 17:29

Type Values Removed Values Added
Summary
  • (es) El complemento Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction para WordPress es vulnerable a la omisión de autenticación en todas las versiones hasta la 2.13.7 incluida. Esto se debe a que la función pms_pb_payment_redirect_link utiliza el valor controlado por el usuario proporcionado a través del parámetro 'pms_payment_id' para autenticar a los usuarios sin ninguna validación de identidad adicional. Esto hace posible que los atacantes no autenticados con conocimiento de una identificación de pago válida inicien sesión como cualquier usuario que haya realizado una compra en el sitio de destino.
CPE cpe:2.3:a:cozmoslabs:membership_\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:*
First Time Cozmoslabs
Cozmoslabs membership \& Content Restriction - Paid Member Subscriptions
CWE NVD-CWE-Other
References () https://plugins.trac.wordpress.org/changeset/3214706/paid-member-subscriptions - () https://plugins.trac.wordpress.org/changeset/3214706/paid-member-subscriptions - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/d3a4fa4d-a7d2-4890-b0f5-5fe69bc5e7ac?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/d3a4fa4d-a7d2-4890-b0f5-5fe69bc5e7ac?source=cve - Third Party Advisory

14 Jan 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 10:15

Updated : 2025-01-22 17:29


NVD link : CVE-2024-12919

Mitre link : CVE-2024-12919

CVE.ORG link : CVE-2024-12919


JSON object : View

Products Affected

cozmoslabs

  • membership_\&_content_restriction_-_paid_member_subscriptions
CWE
CWE-287

Improper Authentication

NVD-CWE-Other