CRITICAL

CVE-2020-36730

CVSS v3

9.3

CRITICAL

EPSS Score

42.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

Technical details

Published
6/7/2023

Frequently asked questions

What is CVE-2020-36730?

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

Is CVE-2020-36730 actively exploited?

Active exploitation of CVE-2020-36730 has not been confirmed. The EPSS score is 42.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-36730?

CVE-2020-36730 has a CVSS v3 base score of 9.3 (CRITICAL severity).

Is CVE-2020-36730 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.