plugin

Imember360 Vulnerabilities

5 known security issues reported for the Imember360 WordPress plugin. Most recent disclosed May 14, 2014.

4 high 1 medium

Running Imember360 on your site? Check whether your installed version is affected.

Scan your site free

iMember360is 3.8.012 - 3.9.001 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.

CVSS:
6.1
Affected:
3.8.012 – 3.9.002
Fixed in:
3.9.002
Disclosed:
May 14, 2014

CVE-2014-3842 on NVD →

iMember360 3.8.012 - 3.9.001 - Missing Authorization

high

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.

CVSS:
7.5
Affected:
3.8.012 – 3.9.001
Fixed in:
3.9.001
Disclosed:
Apr 28, 2014

CVE-2014-3849 on NVD →

iMember360 < 3.9.001 - Missing Authorization and Sensitive Data Exposure

high

The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.

CVSS:
7.5
Affected:
up to 3.9.001
Fixed in:
3.9.001
Disclosed:
Apr 28, 2014

CVE-2014-3848 on NVD →

iMember360 3.8.0.12 - 3.9.001 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbit...

CVSS:
8.8
Affected:
3.8.012 – 3.9.001
Fixed in:
3.9.001
Disclosed:
Apr 24, 2014

CVE-2014-8948 on NVD →

iMember360 3.8.012 - 3.9.001 - Remote Code Execution

high

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue i...

CVSS:
7.2
Affected:
3.8.012 – 3.9.001
Fixed in:
3.9.002
Disclosed:
Apr 24, 2014

CVE-2014-8949 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database