The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the `change_plan_sub_id` parameter in the `process_checkout()` function. This makes it possible for authenticated attackers, with subscriber level access and above, to reference another user's active subscription during checkout to manipulate proration calculations, allowing them to obtain paid lifetime membership plans without payment via the `ppress_process_checkout` AJAX action.
The ProfilePress WordPress plugin contains an authorization bypass vulnerability allowing authenticated users to manipulate subscription parameters during checkout, enabling free access to paid membership plans. Attackers can exploit missing ownership verification on subscription identifiers to bypass payment requirements.
يحتوي مكون ProfilePress على ثغرة في التحقق من الصلاحيات تسمح للمستخدمين المصرح لهم بتجاوز متطلبات الدفع. يمكن للمهاجمين استغلال معاملات الاشتراك الخاصة بمستخدمين آخرين لتعديل حسابات الخصم والحصول على خطط العضويات المدفوعة مجاناً.
A critical authorization flaw in ProfilePress plugin allows authenticated attackers to bypass membership payments by manipulating subscription parameters. This vulnerability enables unauthorized access to premium membership features without completing payment transactions.
Update ProfilePress plugin to version 4.16.12 or later immediately. Implement server-side ownership verification for all subscription parameter changes. Validate that users can only modify their own subscription identifiers during checkout. Apply Web Application Firewall rules to detect suspicious subscription parameter modifications.
قم بتحديث مكون ProfilePress إلى الإصدار 4.16.12 أو أحدث فوراً. طبق التحقق من الملكية على جانب الخادم لجميع تغييرات معاملات الاشتراك. تأكد من أن المستخدمين يمكنهم فقط تعديل معرفات اشتراكاتهم الخاصة. طبق قواعد جدار الحماية لكشف محاولات التلاعب بمعاملات الاشتراك.