ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36833”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36833
Published
2024-10-16
CVSS:
6.3
ShadowTrackr CVSS:
1.3
Summary:
The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying settings and viewing sensitive data.