CVE-2024-1407
Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modification
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to subscribe to, modify, or cancel membership for a user via a forged request granted they can trick a user into performing an action such as clicking on a link.
| CWE | CWE-352 |
| Vendor | strangerstudios |
| Product | paid memberships pro – content restriction, user registration, & paid subscriptions |
| Published | Jun 19, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for strangerstudios paid memberships pro – content restriction, user registration, & paid subscriptions
Be the first to know when new medium vulnerabilities affecting strangerstudios paid memberships pro – content restriction, user registration, & paid subscriptions are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
strangerstudios / Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
0 ≤ 2.12.10
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/c46bcbd1-566d-4b21-84a1-f25e3df7ddc7?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/paid-memberships-pro/tags/2.12.10/includes/functions.php github.com: https://github.com/strangerstudios/paid-memberships-pro/pull/2893 github.com: https://github.com/strangerstudios/paid-memberships-pro/pull/2839 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3058329%40paid-memberships-pro%2Ftrunk&old=3033153%40paid-memberships-pro%2Ftrunk&sfp_email=&sfph_mail=
Credits
Colin Xu