CVE · High

CVE-2022-3383 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.5.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3383 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.5.1 Improper Control of Generation of Code ('Code Injection') High 7.2 < 2.5.1 2.5.1 2022-10-28

CVE-2022-3383

The Ultimate Member plugin for WordPress before version 2.5.1 contains a remote code execution vulnerability in the get_option_value_from_callback function. This function takes user-controlled input and passes it directly to call_user_func(), allowing administrators to execute arbitrary code on the server. Only authenticated users with administrative privileges can exploit this flaw.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.