Description
WordPress Plugin Paid Memberships Pro-Content Restriction, User Registration, & Paid Subscriptions is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to update an order status to paid. WordPress Plugin Paid Memberships Pro-Content Restriction, User Registration, & Paid Subscriptions version 3.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.5 or latest
References
Related Vulnerabilities
Apache HTTP Server CVE-2005-2700 Vulnerability (CVE-2005-2700)
Nginx Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9516)
PHP Other Vulnerability (CVE-2015-4116)
WordPress Plugin WP Open Social Cross-Site Scripting (5.0)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0096)