CVE-2020-36666
Summary
| CVE | CVE-2020-36666 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-27 16:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before 1.3.1, lawyer-directory WordPress plugin before 1.2.9, doctor-listing WordPress plugin before 1.3.6, Hotel Listing WordPress plugin before 1.3.7, fitness-trainer WordPress plugin before 1.4.1, wp-membership WordPress plugin before 1.5.7, sold by the same developer (e-plugins), do not implementing any security measures in some AJAX calls. For example in the file plugin.php, the function iv_directories_update_profile_setting() uses update_user_meta with any data provided by the ajax call, which can be used to give the logged in user admin capabilities. Since the plugins allow user registration via a custom form (even if the blog does not allow users to register) it makes any site using it vulnerable. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | E-plugins | Directory Pro | All | All | All | All |
| Application | E-plugins | Final User | All | All | All | All |
| Application | E-plugins | Fitness Trainer | All | All | All | All |
| Application | E-plugins | Hospital Doctor Directory | All | All | All | All |
| Application | E-plugins | Hotel Directory | All | All | All | All |
| Application | E-plugins | Institutions Directory | All | All | All | All |
| Application | E-plugins | Lawyer Directory | All | All | All | All |
| Application | E-plugins | Photographer-directory | All | All | All | All |
| Application | E-plugins | Producer-retailer | - | All | All | All |
| Application | E-plugins | Real Estate Pro | All | All | All | All |
| Application | E-plugins | Wp Membership | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| e-plugins's profile on CodeCanyon | MISC | codecanyon.net | |
| Multiple e-plugins - Subscriber+ Privilege Escalation WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.