HomeSecurityWP-Members Membership: Vulnerability puts WordPress sites at risk

WP-Members Membership: Vulnerability puts WordPress sites at risk

A cross-site scripting (XXS) vulnerability in the WordPress WP-Members Membership plugin could put thousands of sites at risk.

WP-Members Membership Vulnerability

The vulnerability was reported to Wordfence by WordPress developer Webbernaut as part of the Bug Bounty Extravaganza program . Webbernaut received a $500 bounty for reporting the vulnerability.

The WP-Members Membership Plugin is currently installed on over 60,000 WordPress websites.

See also: LayerSlider: Critical vulnerability in WordPress plugin

“ The vulnerability allows threat actors to inject JavaScript via the X-Forwarded-For header, which is used by the plugin for logging purposes ,” Wordfence says . “ When viewed by an administrator, the malicious code is executed within the administrator’s browser session and allows the creation of malicious administrator users and changes to the settings of an affected website, which could lead to a complete takeover of the website .”

The vulnerability affects all versions of WP-Members Membership up to and including 3.4.9.2.

Wordfence said that the vulnerability was partially fixed in version 3.4.9.2 and fully in the version 3.4.9.3.

See also: Popup Builder plugin: Vulnerability puts thousands of WordPress sites at risk

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

WP-Members Membership: Vulnerability puts WordPress sites at risk
WP-Members Membership: Vulnerability puts WordPress sites at risk

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

See also: WordPress sites use visitor browsers to hack other sites

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.

Source: securityaffairs.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS