CVE-2020-36832

CRITICAL EXPLOITED

Ultimate Membership Pro <8.6 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-36832 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-10-15
CWE
CWE-287
Status published
Products (1)
wpindeed/Indeed Membership Pro 7.3 - 8.6.1
Published Oct 16, 2024
Tracked Since Feb 18, 2026