CVE Database /
CVE-2019-10673
CVE · High
CVE-2019-10673 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-10673
|
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 2.0.40
|
2.0.40 |
2019-04-01 |
—
|
CVE-2019-10673
The Ultimate Member plugin before version 2.0.40 contains a cross-site request forgery flaw in the user profile editing functionality that permits attackers to modify an administrator's email address without proper verification. By changing the admin email through a forged request, an attacker can then use WordPress's password reset feature to gain control of the administrator account, leading to potential unauthorized access to sensitive data and execution of malicious code.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings