CVE Database /
CVE-2020-36155
CVE · Critical
CVE-2020-36155 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-36155
|
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.12 |
Improper Privilege Management |
Critical
9.8
|
< 2.1.12
|
2.1.12 |
2020-11-09 |
—
|
CVE-2020-36155
The Ultimate Member plugin before version 2.1.12 contained an unauthenticated privilege escalation vulnerability in its registration process. An attacker could manipulate array parameters submitted during user registration to modify sensitive user metadata fields, including wp_capabilities, which controls user roles and permissions. Because the registration form accepted and processed arbitrary metadata without proper validation, an attacker could grant themselves administrator access by injecting wp_capabilities[administrator] during signup.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings