CVE-2020-36832: Wpindeed Indeed Membership Pro

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.

Affected products

  • Wpindeed Indeed Membership Pro: from 7.3, before 8.6.1 (fixed in 8.6.1)
  • Wpindeed Ultimate Membership Pro: from 7.3, before 8.6.1 (fixed in 8.6.1)

Published 2024-10-16. Last modified 2026-06-17.