codecanyon.net
https://codecanyon.net/item/ultimate-membership-pro-wordpress-plugin/12159253 CVE-2020-36832
CRITICAL
Indeed Membership Pro 7.3 - 8.6 - Authentication Bypass
Record summary
CVE-2020-36832 has a selected CVSS score of 9.8 (critical).
Description
The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Ultimate Membership Pro plugin for WordPressBrowse azzaroco / Ultimate Membership Pro plugin for WordPress | VulnCheck | Version data not supplied | |
Indeed Membership ProBrowse wpindeed / Indeed Membership ProDefault status: unaffected | CVE List | 7.3 to < 8.6.1 | affected |
ultimate_membership_proBrowse wpindeed / ultimate_membership_proDefault status: unknown | CVE List | 7.3 to < 8.6.1 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36832 wpscan.com
https://wpscan.com/vulnerability/9811025e-ab17-4255-aaaf-4f0306f5d281 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/a5341bbd-55bd-41ad-b5d1-d6b56c141277?source=cve