First published: Mon Jan 04 2021(Updated: )
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-36156 is critical with a CVSS score of 8.8.
CVE-2020-36156 affects the Ultimate Member plugin before version 2.1.12.
CVE-2020-36156 is an authenticated privilege escalation vulnerability via profile update in the Ultimate Member plugin for WordPress.
An attacker with wp-admin access to the profile.php page can supply a parameter to elevate their own role.
To fix CVE-2020-36156, it is recommended to update the Ultimate Member plugin to version 2.1.12 or later.