An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:23:09.548Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2020-36155
No data.
Status : Modified
Published: 2021-01-04T18:15:13.620
Modified: 2024-11-21T05:28:49.863
Link: CVE-2020-36155
No data.
OpenCVE Enrichment
No data.