The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpindeed
Wpindeed ultimate Membership Pro |
|
CPEs | cpe:2.3:a:wpindeed:ultimate_membership_pro:*:*:*:*:*:*:*:* | |
Vendors & Products |
Wpindeed
Wpindeed ultimate Membership Pro |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID. | |
Title | Indeed Membership Pro 7.3 - 8.6 - Authentication Bypass | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:38.406Z
Updated: 2024-10-16T18:03:20.662Z
Reserved: 2024-10-15T18:07:00.693Z
Link: CVE-2020-36832
Vulnrichment
Updated: 2024-10-16T17:36:48.782Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T07:15:07.637
Modified: 2024-10-16T16:38:14.557
Link: CVE-2020-36832
Redhat
No data.