CVE Database /
CVE-2018-20965
CVE · Medium
CVE-2018-20965 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-0585, CVE-2018-0586, CVE-2018-0587, CVE-2018-0588, CVE-2018-0590, CVE-2018-20965, CVE-2018-0589
|
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 2.0.4
|
2.0.4 |
2018-05-10 |
—
|
CVE-2018-0585, CVE-2018-0586, CVE-2018-0587, CVE-2018-0588, CVE-2018-0590, CVE-2018-20965, CVE-2018-0589
The Ultimate Member plugin before version 2.0.4 contains six distinct security flaws that allow attackers to perform multiple types of attacks. These vulnerabilities include reflected cross-site scripting, directory traversal via both shortcodes and AJAX functions, unauthorized file uploads, and bypasses of access controls through the Forms page and role processing mechanisms. The plugin versions prior to 2.0.4 are affected by these issues, and users should update immediately to address all six security weaknesses.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings