Description
WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to change user passwords and potentially take over administrator accounts. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.11.0 or latest
References
https://lana.codes/lanavdb/3a841453-d083-4f97-a7f1-b398c7304284/
https://plugins.svn.wordpress.org/wc-multivendor-membership/trunk/readme.txt