YourMembership WordPress Plugin Unauthorized Data Access Vulnerability
Vulnerability
A vulnerability exists in the YourMembership Single Sign On - YM SSO Login plugin for WordPress, in all versions through 1.1.7. The issue arises from a missing capability check in the 'moym_display_test_attributes' function, allowing unauthenticated attackers to access and read profile data from the latest SSO login.
Impact
Exploitation of this vulnerability allows for unauthorized access to sensitive profile data via the 'moym_display_test_attributes' function.
Reproduction
To reproduce this vulnerability, send a request to the WordPress site with the 'option' parameter set to 'moymsso' or 'show_attr', without any authentication. The 'moym_display_test_attributes' function will be executed, exposing the basic profile attributes of the user.
Remediation
No known patch is available. It is recommended to uninstall the affected plugin and find a replacement.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
