4.3
CVSSv2

CVE-2014-3849

Published: 23/05/2014 Updated: 27/05/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The iMember360 plugin 3.8.012 up to and including 3.9.001 for WordPress does not properly restrict access, which allows remote malicious users to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imember360 imember360 3.9.001

imember360 imember360 3.9.000

imember360 imember360 3.8.013

imember360 imember360 3.8.014

imember360 imember360 3.8.012

Exploits

------------ BACKGROUND ------------ "iMember360is a WordPress plugin that will turn a normal WordPress site into a full featured membership site It includes all the protection controls you can imagine, yet driven by Infusionsoft's second-to-none CRM and e-commerce engine" -- imember360com/ This plugin is hailed by some as being one of t ...