wpindeed Vulnerabilities and Affected Products
Vulnerabilities associated with Indeed Membership Pro.
Products
Clear product- Debug Assistant2 vulnerabilities
- Indeed Membership Pro2 vulnerabilities
- ultimate_membership_pro2 vulnerabilities
- Ultimate Learning Pro1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36833MEDIUM | Indeed Membership Pro 7.3 - 8.6 - Missing Authorization ChecksThe Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying settings and viewing sensitive data. CWE-862Oct 16, 2024 | CVSS6.3v3.1 | EPSS0.354% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36832CRITICAL | Indeed Membership Pro 7.3 - 8.6 - Authentication BypassThe Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. CWE-287Oct 16, 2024 | CVSS9.8v3.1 | EPSS0.691% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |