Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace Insecure Direct Object Reference (2.10.7) - Vulnerability Database

WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace Insecure Direct Object Reference (2.10.7)

Description

WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to change user passwords and potentially take over administrator accounts. WordPress Plugin WCFM Membership-WooCommerce Memberships for Multivendor Marketplace version 2.10.7 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 2.11.0 or latest