The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46781 | The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented nonce validation function on multiple functions. This makes it possible for unauthenticated attackers to modify, or delete user meta and plugin options which can lead to limited privilege escalation. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:47:51.555Z
Reserved: 2024-06-03T12:57:51.027Z
Link: CVE-2024-5596
Updated: 2024-08-01T21:18:06.636Z
Status : Awaiting Analysis
Published: 2024-06-22T06:15:11.470
Modified: 2026-04-08T18:22:09.020
Link: CVE-2024-5596
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:49Z
Weaknesses
EUVD