PT-2026-86471 · WordPress · Memberdash
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MemberDash versions prior to 1.8.6
Description
An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. This allows unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID via the
id parameter during registration, leading to full account takeover without notifying the victim.Recommendations
Update MemberDash to version 1.8.6 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Memberdash