CVE-2024-1409
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-1409 is a Stored Cross-Site Scripting vulnerability affecting the Paid Membership Plugin, specifically versions up to and including 4.15.0, used in WordPress websites. This issue allows authenticated attackers with contributor-level permissions and above to inject malicious scripts through the [reg-select-role] shortcode, located in the plugin's Registration and Login forms. These scripts will execute whenever a user accesses an injected page, posing a significant security risk. The root cause is insufficient input sanitization and output escaping on user-supplied attributes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.