Vulnerability Description
The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying settings and viewing sensitive data.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/9811025e-ab17-4255-aaaf-4f0306f5d281
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ab1cc1ef-d0e0-491d-91a
FAQ
What is CVE-2020-36833?
CVE-2020-36833 is a vulnerability with a CVSS score of 6.3 (MEDIUM). The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenti...
How severe is CVE-2020-36833?
CVE-2020-36833 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36833?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.