CyberRota Analysis
AI-GeneratedThe WCFM Membership plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability that allows authenticated attackers with vendor-level access to alter any user's role to 'wcfm_vendor' by manipulating their membership plan. This could lead to unauthorized access and privilege escalation within the platform. WordPress site administrators and users of the affected plugin should prioritize applying updates to mitigate this high-severity risk.
Original NVD Description
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.