CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ultimatemember 1Ultimate Member Nov 21, 2024 Jan 4, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the paramet...Show more |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Jan 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the w...Show more |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Jan 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos...Show more |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ultimate-member plugin before 2.0.54 for WordPress has XSS. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-member plugin before 2.0.4 for WordPress has XSS. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Aug 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Jun 24, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is conn...Show more |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Jun 21, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id p...Show more |
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary...Show more |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Oct 9, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary...Show more |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Jul 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 May 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Ultimatemember 1Ultimate Member Nov 21, 2024 Feb 16, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable. |
1Ultimatemember 1Ultimate Member May 13, 2026 Sep 11, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php. |