Description
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:23:09.548Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2020-36155
No data.
Status : Modified
Published: 2021-01-04T18:15:13.620
Modified: 2024-11-21T05:28:49.863
Link: CVE-2020-36155
No data.
OpenCVE Enrichment
No data.
Weaknesses