Vulnerabilities
Vulnerable Software
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-07-04
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
5.4
EPSS Score
0.004
Published
2018-05-14
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-02-16


Contact Us

Shodan ® - All rights reserved