9.8
CVE-2020-36832
- EPSS 0.47%
- Veröffentlicht 16.10.2024 07:15:07
- Zuletzt bearbeitet 16.10.2024 16:38:14
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Indeed Membership Pro 7.3 - 8.6 - Authentication Bypass
The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.
Mögliche Gegenmaßnahme
Indeed Membership Pro: Update to version 8.6.1, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Indeed Membership Pro
Version
[7.3, 8.6.1)
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerwpindeed
≫
Produkt
ultimate_membership_pro
Default Statusunknown
Version <
8.6.1
Version
7.3
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.636 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.