CVE-2020-36730

HIGH

WordPress CMP <3.8.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2020-36730

Scores

CVSS v3 8.3
EPSS 0.4636
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
niteo/CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 3.8.1
niteothemes/cmp < 3.8.1
Published Jun 07, 2023
Tracked Since Feb 18, 2026