Skip to main content

Threat intelligence

WishList Member X < 3.26.7 - Authenticated (Subscriber+) Privilege Escalation

CVE-2024-37107 · wishlist-member-x

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Wishlist Member X at a vulnerable version. How SiteRespond intelligence works

Vulnerability
WishList Member X < 3.26.7 - Authenticated (Subscriber+) Privilege Escalation
Affected software
wishlist-member-x(Plugin)
Affected versions
  • < 3.26.7
Authentication
Authenticated (see advisory title)
Vulnerability type
Privilege escalation
Published
20 June 2024
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
May allow a lower-privilege user to perform actions reserved for administrators.
Source

Data imported from Wordfence Intelligence (advisory e78f4832-6d14-4eef-8e4b-f4136b0c1902). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Wishlist Member X version against this catalog when the Defence plugin is connected to your WordPress site.