CVE-2020-36156: Critical severity ultimate member vulnerability
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36156?
The severity of CVE-2020-36156 is critical with a CVSS score of 8.8.
How does CVE-2020-36156 affect the Ultimate Member plugin?
CVE-2020-36156 affects the Ultimate Member plugin before version 2.1.12.
What is the vulnerability in CVE-2020-36156?
CVE-2020-36156 is an authenticated privilege escalation vulnerability via profile update in the Ultimate Member plugin for WordPress.
How can an attacker exploit CVE-2020-36156?
An attacker with wp-admin access to the profile.php page can supply a parameter to elevate their own role.
What is the recommended action to fix CVE-2020-36156?
To fix CVE-2020-36156, it is recommended to update the Ultimate Member plugin to version 2.1.12 or later.