HTTP: WordPress Paid Memberships Pro Plugin pmpro_getCheckoutButton Stored Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against WordPress Paid Memberships Pro Plugin. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

Affected Products

Strangerstudios paid_memberships_pro

References

CVE: CVE-2022-4830

Short Name
HTTP:XSS:WP-PMPRP-GETCHKOUTBT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2022-4830 Cross-Site Memberships Paid Plugin Pro Scripting Stored WordPress pmpro_getCheckoutButton
Release Date
03/23/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3716
False Positive
Unknown
Vendors

Strangerstudios

Found a potential security threat?