CVE-2020-36832
CRITICAL EXPLOITEDUltimate Membership Pro <8.6 - Auth Bypass
Title source: llmExploitation Summary
CVE-2020-36832 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.
References (3)
Core 3
Core References
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/a5341bbd-55bd-41ad-b5d1-d6b56c141277?source=cve
Third Party Advisory
https://wpscan.com/vulnerability/9811025e-ab17-4255-aaaf-4f0306f5d281
Scores
CVSS v3
9.8
EPSS
0.0067
EPSS Percentile
47.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
VulnCheck KEV
2024-10-15
CWE
CWE-287
Status
published
Products (1)
wpindeed/Indeed Membership Pro
7.3 - 8.6.1
Published
Oct 16, 2024
Tracked Since
Feb 18, 2026