Vulnerabilities
Vulnerable Software
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (or any custom Ultimate Member role) and effectively be granted those privileges.
CVSS Score
10.0
EPSS Score
0.015
Published
2021-01-04
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
CVSS Score
5.3
EPSS Score
0.011
Published
2020-01-13
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
CVSS Score
5.4
EPSS Score
0.007
Published
2019-08-12
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
CVSS Score
5.4
EPSS Score
0.005
Published
2019-08-12
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
CVSS Score
5.4
EPSS Score
0.007
Published
2019-08-12


Contact Us

Shodan ® - All rights reserved