Input validation vulnerability in Indeed Membership Pro 8.6.2

The Ultimate Membership Pro plugin for WordPress is not secure in versions up to 8.6.1. It is possible for unauthenticated attackers to perform actions such as deleting users and coupons without the site administrator’s permission. This is due to the lack of validation on various AJAX functions. To protect against this, a site administrator should be aware of the vulnerability and take measures to prevent attackers from tricking them into clicking on malicious links.

Detected in:

Indeed Membership Pro fixed vulnerable versions: >= * < 8.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.