Learn about CVE-2020-36157, a critical vulnerability in Ultimate Member plugin for WordPress allowing unauthenticated privilege escalation. Find mitigation steps and best practices here.
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles.
Understanding CVE-2020-36157
This CVE involves a vulnerability in the Ultimate Member plugin for WordPress that allows unauthenticated privilege escalation through user roles.
What is CVE-2020-36157?
The lack of filtering on the role parameter during the registration process enables an attacker to supply the role parameter with a WordPress capability, granting unauthorized privileges.
The Impact of CVE-2020-36157
The vulnerability has a CVSS base score of 10 (Critical) with high impacts on confidentiality, integrity, and availability. It requires no privileges for exploitation and has a low attack complexity.
Technical Details of CVE-2020-36157
The technical aspects of this CVE are as follows:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your systems from CVE-2020-36157 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates