CVE-2022-1903

CVE-2022-1903

The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

Source: CVE-2022-1903

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다