Description
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:23:09.548Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2020-36155
No data.
Status : Modified
Published: 2021-01-04T18:15:13.620
Modified: 2024-11-21T05:28:49.863
Link: CVE-2020-36155
No data.
OpenCVE Enrichment
No data.
Weaknesses