CyberRota Analysis
AI-GeneratedThe MemberDash plugin for WordPress is critically vulnerable due to an Insecure Direct Object Reference that allows unauthenticated attackers to manipulate the 'id' parameter, enabling them to change any user's password, including that of administrators. This flaw poses a significant risk of account takeover without user notification, making it imperative for all WordPress site administrators using this plugin to prioritize immediate updates to version 1.8.6 or later. Organizations relying on WordPress for user management should take swift action to mitigate potential exploitation.
Original NVD Description
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim.