Critical Security Vulnerabilities in WordPress (CVE-2024-9636, CVE-2024-12919)

Published On: Jan 18, 2025 15:12

Advisory No: TZCERT-SA-25-0052

Source: Wordfence

Software Affected: post-grid, paid-member-subscriptions

Overview

WordPress is vulnerable to critical vulnerabilities. Exploitation of these vulnerabilities may allow an unauthenticated attacker to execute arbitrary code.

Description

WordPress plugins post-grid, and paid-member-subscriptions are affected by the vulnerabilities tracked as CVE-2024-9636, and CVE-2024-12919 with a CVSS score of 9.8 each. The plugins are vulnerable due to the failure of the plugin to properly restrict what user meta can be updated during profile registration; and the use of user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. The vulnerabilities allow unauthenticated attackers to register on the site as an administrator; and log in as any user who has purchased on the targeted site.

Impact

Successful exploitation of these vulnerabilities may allow the attackers to gain escalated privileges on the affected system.

Solution

WordPress has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident