WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace Insecure Direct Object Reference - CVE-2023-2276 - Vulnerability Database

WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace Insecure Direct Object Reference - CVE-2023-2276

Critical
Reference: CVE-2023-2276
Title: WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace Insecure Direct Object Reference
Overview:

WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to change user passwords and potentially take over administrator accounts. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.7 is vulnerable prior versions may also be affected.