6.8
CVSSv2

CVE-2014-8948

Published: 16/11/2014 Updated: 17/11/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 up to and including 3.9.001 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbitrary commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imember360 imember360 3.9.000

imember360 imember360 3.8.012

imember360 imember360 3.8.013

imember360 imember360 3.8.014

imember360 imember360 3.9.001

Exploits

------------ BACKGROUND ------------ "iMember360is a WordPress plugin that will turn a normal WordPress site into a full featured membership site It includes all the protection controls you can imagine, yet driven by Infusionsoft's second-to-none CRM and e-commerce engine" -- imember360com/ This plugin is hailed by some as being one of t ...