cleantalk

Vulnerabilities and Security Researches

Security report for CVE Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions > CVE-2024-37277

CVE, Research URL

CVE-2024-37277

Published on
Nov 01, 2024
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
Affected versions
Min -, max 3.0.5.
Status
vulnerable