WordPress Plugin Vulnerabilities

Ultimate Membership Pro < 8.7 - Cross-Site Request Forgery allowing Arbitrary Account Deletion and Creation

Description

While confirming the issues from https://wpvulndb.com/vulnerabilities/10086 have been remediated, two CSRF issues were identified, allowing attackers to make logged in administrator delete arbitrary accounts, as well as create a new administrator account. Other CSRF may be present but haven't been checked.

February 17th, 2020 - Envato Notified
February 22nd, 2020 - New version released (8.7), fixing the reported issues, as well as putting CSRF checks on all other actions as per recommendations.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
ErwanLR
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2020-02-24 (about 5 years ago)
Added
2020-02-24 (about 5 years ago)
Last Updated
2020-03-07 (about 5 years ago)

Other