WordPress Plugin Vulnerabilities
Ultimate Membership Pro < 8.7 - Cross-Site Request Forgery allowing Arbitrary Account Deletion and Creation
Description
While confirming the issues from https://wpvulndb.com/vulnerabilities/10086 have been remediated, two CSRF issues were identified, allowing attackers to make logged in administrator delete arbitrary accounts, as well as create a new administrator account. Other CSRF may be present but haven't been checked.
February 17th, 2020 - Envato Notified
February 22nd, 2020 - New version released (8.7), fixing the reported issues, as well as putting CSRF checks on all other actions as per recommendations.
Proof of Concept
Affects Plugins
References
Classification
Type
CSRF
OWASP top 10
CWE
Miscellaneous
Original Researcher
ErwanLR
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2020-02-24 (about 5 years ago)
Added
2020-02-24 (about 5 years ago)
Last Updated
2020-03-07 (about 5 years ago)