CVE-2020-36833

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying settings and viewing sensitive data.
Configurations

No configuration.

History

No history.

Information

Published : 2024-10-16 07:15

Updated : 2024-10-16 16:38


NVD link : CVE-2020-36833

Mitre link : CVE-2020-36833

CVE.ORG link : CVE-2020-36833


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization