← Back
CVE-2026-3445
high
CVSS 7.1
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass i...
Summary
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the...
AI summary openai / gpt-4o
WordPressのProfilePressプラグインは、バージョン4.16.11まで、未承認のメンバーシップ支払いバイパスの脆弱性があります。認証された攻撃者が他のユーザーのサブスクリプションを利用して、支払いなしに有料プランを取得できる恐れがあります。
❓ What is the problem
ProfilePressプラグインの未承認のメンバーシップ支払いバイパス脆弱性。
📍 Affected scope
WordPressのProfilePressプラグインバージョン4.16.11まで。
🔥 Severity
認証された攻撃者が支払いなしに有料の会員プランを取得できるため、高いセキュリティリスクがあります。CVSSスコアは7.1です。
🔧 How to fix
ProfilePressプラグインを最新版にアップデートすることで修正可能です。
🛡️ Workaround
特に無し。迅速にプラグインを更新することを推奨します。
🔍 Detection
プラグインのバージョンを確認し、4.16.11以前であれば影響を受ける可能性があります。
References
- web [email protected]
- web [email protected]