WishList Member
- <= 3.30.1
A vulnerability exists in the WishList Member plugin for WordPress, in versions up to and including 3.30.1. The issue stems from missing authorization checks in the 'export_settings' function, which allows authenticated users to access the REST API Secret Key. This key, if obtained, can be used to authenticate with the WishList Member API, create new membership levels with administrative privileges, and register users with administrator rights, potentially leading to a complete takeover of the site.
Exploitation of this vulnerability allows for unauthorized access to the REST API Secret Key, which can be used to gain administrative privileges on the WordPress site, including the ability to create new admin users and take over the site.
Users are advised to update the WishList Member plugin to version 3.31.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.