CVE-2024-5031
CVSS 3.1 Score 8.5 of 10 (high)
Details
Summary
CVE-2024-5031 is a vulnerability affecting the Memberpress plugin for WordPress. This issue allows authenticated attackers, with Contributor-level access and above, to execute Blind Server-Side Request Forgeries via the 'mepr-user-file' shortcode. By exploiting this vulnerability, attackers can make web requests to arbitrary locations from the web application, potentially gaining unauthorized access to internal services and modifying sensitive information. This security flaw poses a serious threat, and all users running affected versions (up to and including 1.11.29) are encouraged to update as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.