CVE · Medium

CVE-2018-20965 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-0585, CVE-2018-0586, CVE-2018-0587, CVE-2018-0588, CVE-2018-0590, CVE-2018-20965, CVE-2018-0589 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.0.4 2.0.4 2018-05-10

CVE-2018-0585, CVE-2018-0586, CVE-2018-0587, CVE-2018-0588, CVE-2018-0590, CVE-2018-20965, CVE-2018-0589

The Ultimate Member plugin before version 2.0.4 contains six distinct security flaws that allow attackers to perform multiple types of attacks. These vulnerabilities include reflected cross-site scripting, directory traversal via both shortcodes and AJAX functions, unauthorized file uploads, and bypasses of access controls through the Forms page and role processing mechanisms. The plugin versions prior to 2.0.4 are affected by these issues, and users should update immediately to address all six security weaknesses.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.