The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if 2Checkout (deprecated since version 2.6) or PayPal Express is set as the payment method and a custom user field is added that is only visible at profile, and not visible at checkout according to its settings.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-11-18T01:54:35.162Z

Updated: 2023-11-18T01:54:35.162Z

Reserved: 2023-11-17T12:09:54.958Z


Link: CVE-2023-6187

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-18T02:15:49.333

Modified: 2023-11-24T23:02:44.967


Link: CVE-2023-6187

JSON object: View

cve-icon Redhat Information

No data.

CWE