CVE-2020-36666 is a critical vulnerability affecting multiple WordPress plugins developed by e-plugins, including directory-pro, final-user-wp-frontend-user-profiles, and wp-membership. These plugins fail to implement security measures in certain AJAX calls, allowing authenticated users to manipulate user metadata. Specifically, a logged-in user can exploit this flaw to grant themselves administrative privileges, even on sites where user registration is typically restricted. The vulnerability carries a CVSS score of 8.8 (High), indicating a severe risk. Its attack vector is network-based with low attack complexity, requiring only low privileges and no user interaction. Successful exploitation can lead to complete compromise of confidentiality, integrity, and availability of the affected system. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.5CPE matchmatch criteria | cpe:2.3:a:e-plugins:directory_pro:*:*:*:*:*:wordpress:*:* | ||
< 1.2.2CPE matchmatch criteria | cpe:2.3:a:e-plugins:final_user:*:*:*:*:*:wordpress:*:* | ||
< 1.4.1CPE matchmatch criteria | cpe:2.3:a:e-plugins:fitness_trainer:*:*:*:*:*:wordpress:*:* | ||
< 1.3.6CPE matchmatch criteria | cpe:2.3:a:e-plugins:hospital_\&_doctor_directory:*:*:*:*:*:wordpress:*:* | ||
< 1.3.7CPE matchmatch criteria | cpe:2.3:a:e-plugins:hotel_directory:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.