Description

WordPress Plugin Paid Memberships Pro-Content Restriction, User Registration, & Paid Subscriptions is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to update an order status to paid. WordPress Plugin Paid Memberships Pro-Content Restriction, User Registration, & Paid Subscriptions version 3.0.4 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 3.0.5 or latest

References

Related Vulnerabilities