Vulnerabilities
Vulnerable Software
Ultimatemember:  >> Ultimate Member  Security Vulnerabilities
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.
CVSS Score
9.9
EPSS Score
0.009
Published
2021-01-04
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (or any custom Ultimate Member role) and effectively be granted those privileges.
CVSS Score
10.0
EPSS Score
0.015
Published
2021-01-04
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
CVSS Score
5.3
EPSS Score
0.011
Published
2020-01-13
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
CVSS Score
5.4
EPSS Score
0.007
Published
2019-08-12
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
CVSS Score
5.4
EPSS Score
0.005
Published
2019-08-12
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
CVSS Score
5.4
EPSS Score
0.007
Published
2019-08-12
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-08-12
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-08-12
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-08-12
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such a modification, one first needs to (for example) intercept an upload-picture request and modify the user_id parameter.
CVSS Score
4.3
EPSS Score
0.002
Published
2019-06-24


Contact Us

Shodan ® - All rights reserved