PT-2026-78305 · WordPress · Membership For Woocommerce
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Membership For WooCommerce versions prior to 3.1.2
Description
An issue exists where the plugin fails to verify if an API consumer secret has been generated before comparing it with the secret provided in a request. This allows unauthenticated attackers to access REST routes and disclose membership plan details of any user on sites where the API is enabled but no keys have been generated.
Recommendations
Update Membership For WooCommerce to version 3.1.2 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Membership For Woocommerce