// For flags

CVE-2020-36155

Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Meta

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.

Se detectó un problema en el plugin Ultimate Member versiones anteriores a 2.1.12 para WordPress, también se conoce como una Escalada de Privilegios No Autenticada por medio de User Meta.&#xa0;Un atacante podría suministrar un parámetro de matriz para metadatos confidenciales, tal y como el usuario meta de wp_capabilities que define el rol de un usuario.&#xa0;Durante el proceso de registro, los detalles de registro enviados fueron pasados a la función update_profile y cualquier metadato fue aceptado, por ejemplo, wp_capabilities[administrador] para el acceso de administrador.

*Credits: Chloe Chamberland
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-11-09 CVE Published
  • 2021-01-04 CVE Reserved
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-09-21 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ultimatemember
Search vendor "Ultimatemember"
Ultimate Member
Search vendor "Ultimatemember" for product "Ultimate Member"
< 2.1.12
Search vendor "Ultimatemember" for product "Ultimate Member" and version " < 2.1.12"
wordpress
Affected