Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook
Vulnerability Description
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by forging a charge.refunded webhook event containing a victim's subscription ID, setting the target member's account_state to 'inactive' and triggering cancellation hooks, transaction-record status changes, and cancellation notification emails. This vulnerability is exploitable only on installations where no Stripe webhook signing secret has been configured, which is the default out-of-the-box state; sites that have configured the stripe-webhook-signing-secret option are routed to the properly verified HMAC path and are not affected.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Wpinsider-1 Simple Membership 授权问题漏洞
Vulnerability Description
Wpinsider-1 Simple Membership是Wpinsider-1公司的一款专注于用户注册与访问管理的 WordPress 插件,主要用途是为网站添加会员功能,支持用户注册、登录、内容访问限制等典型操作。 Wpinsider-1 Simple Membership 4.7.5及之前版本存在授权问题漏洞,该漏洞源于未正确验证用户授权,可能导致未经身份验证的攻击者通过伪造包含受害者订阅ID的charge.refunded webhook事件,将目标成员账户状态设置为非活动,从而停用任意成员账户
CVSS Information
N/A
Vulnerability Type
N/A