Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D50DBFB9-5759-415A-8638-73C622B44793
HistoryNov 18, 2023 - 12:00 a.m.

Paid Memberships Pro < 2.12.4 - Subscriber+ Arbitrary File Upload

2023-11-1800:00:00
wpscan.com
6
paid memberships pro
security vulnerability
file upload
authentication bypass
payment methods

AI Score

7

Confidence

High

EPSS

0.002

Percentile

58.8%

Description The plugin does not properly validate file type in its pmpro_paypalexpress_session_vars_for_user_fields() function, which could allow any authenticated users, such as subscriber to upload arbitrary files on the server. Note: Exploitation of the issue requires 2Checkout (deprecated since version 2.6) or PayPal Express to be set set as the payment method and a custom user field is added that is only visible at profile, and not visible at checkout according to its settings.

AI Score

7

Confidence

High

EPSS

0.002

Percentile

58.8%

Related for WPVDB-ID:D50DBFB9-5759-415A-8638-73C622B44793