Back

MEDIUM

WP-Members Membership <= 3.4.7.3 - Missing Authorization to Settings Update

Published Jul 12, 2023

Description

The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jul 12, 2023
Updated Apr 8, 2026
Reserved May 24, 2023
CISA Vulnrichment
Updated Oct 23, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Wordfence
Published Jul 12, 2023
Updated Apr 8, 2026
Exploited since n/a
EUVD-2023-34317