YourMembership WordPress Plugin Unauthorized Data Access Vulnerability

Vulnerability

A vulnerability exists in the YourMembership Single Sign On - YM SSO Login plugin for WordPress, in all versions through 1.1.7. The issue arises from a missing capability check in the 'moym_display_test_attributes' function, allowing unauthenticated attackers to access and read profile data from the latest SSO login.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive profile data via the 'moym_display_test_attributes' function.

Reproduction

To reproduce this vulnerability, send a request to the WordPress site with the 'option' parameter set to 'moymsso' or 'show_attr', without any authentication. The 'moym_display_test_attributes' function will be executed, exposing the basic profile attributes of the user.

Remediation

No known patch is available. It is recommended to uninstall the affected plugin and find a replacement.

Added: Oct 15, 2025, 9:36 AM
Updated: Oct 15, 2025, 9:36 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.4
remediation
0.0
relevance
0.8
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.