The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.
References
Configurations
History
No history.
Information
Published : 2023-07-12 05:15
Updated : 2023-11-07 04:13
NVD link : CVE-2023-2869
Mitre link : CVE-2023-2869
CVE.ORG link : CVE-2023-2869
JSON object : View
Products Affected
wp-members_project
- wp-members
CWE
No CWE.