CVE-2020-36833

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying settings and viewing sensitive data.
Configurations

No configuration.

History

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) El complemento Indeed Membership Pro para WordPress es vulnerable a la omisión de la autorización debido a la falta de comprobaciones de capacidad en varias acciones AJAX en las versiones 7.3 a 8.6. Esto hace posible que un atacante autenticado, con un permiso mínimo, como un suscriptor, realice una variedad de acciones, como modificar configuraciones y ver datos confidenciales.

16 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 07:15

Updated : 2024-10-16 16:38


NVD link : CVE-2020-36833

Mitre link : CVE-2020-36833

CVE.ORG link : CVE-2020-36833


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization