CVE-2024-1409

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Mar 13, 2024

Summary

CVE-2024-1409 is a Stored Cross-Site Scripting vulnerability affecting the Paid Membership Plugin, specifically versions up to and including 4.15.0, used in WordPress websites. This issue allows authenticated attackers with contributor-level permissions and above to inject malicious scripts through the [reg-select-role] shortcode, located in the plugin's Registration and Login forms. These scripts will execute whenever a user accesses an injected page, posing a significant security risk. The root cause is insufficient input sanitization and output escaping on user-supplied attributes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share