Usersultra
usersultra
7 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (availa...Show more |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. |
Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote paramet...Show more |