SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WordPress plugin ARMember Authorization Bypass

Category: WEB-ATTACKS      

CVE-2022-1903 The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username.


Relevant Information