CVE-2020-36157: Critical severity ultimate member vulnerability
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (or any custom Ultimate Member role) and effectively be granted those privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36157?
CVE-2020-36157 is a vulnerability in the Ultimate Member plugin for WordPress that allows unauthenticated privilege escalation via user roles.
How severe is CVE-2020-36157?
CVE-2020-36157 is classified as critical with a severity score of 9.8 out of 10.
What is the affected software?
The affected software is the Ultimate Member plugin for WordPress version up to 2.1.12.
How can an attacker exploit CVE-2020-36157?
An attacker can exploit CVE-2020-36157 by supplying a malicious role parameter during the registration process.
Are there any references for CVE-2020-36157?
Yes, you can find more information about CVE-2020-36157 at the following references: [link1], [link2], [link3].