PT-2021-11937 · WordPress · Ultimate Member

Chloe Chamberland

·

Published

2021-01-04

·

Updated

2021-01-08

·

CVE-2020-36156

CVSS v3.1

9.9

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: Ultimate Member plugin versions prior to 2.1.12
Description: An issue allows authenticated privilege escalation via profile update. Any user with access to the profile.php page can supply the parameter um-role with a value set to any role, such as Administrator, during a profile update, effectively escalating their privileges.
Recommendations: For Ultimate Member plugin versions prior to 2.1.12, update to version 2.1.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the profile.php page and the um-role parameter to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36156

Affected Products

Ultimate Member