5
CVSSv2

CVE-2014-3848

Published: 23/05/2014 Updated: 27/05/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The iMember360 plugin prior to 3.9.001 for WordPress does not properly restrict access, which allows remote malicious users to obtain database credentials via the i4w_dbinfo parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imember360 imember360

Exploits

------------ BACKGROUND ------------ "iMember360is a WordPress plugin that will turn a normal WordPress site into a full featured membership site It includes all the protection controls you can imagine, yet driven by Infusionsoft's second-to-none CRM and e-commerce engine" -- imember360com/ This plugin is hailed by some as being one of t ...