CVE-2024-12276
- EPSS 0.08%
- Veröffentlicht 21.02.2025 10:15:10
- Zuletzt bearbeitet 25.02.2025 03:34:14
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insuf...
CVE-2025-0318
- EPSS 0.28%
- Veröffentlicht 18.01.2025 06:15:28
- Zuletzt bearbeitet 25.02.2025 22:09:05
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages...
CVE-2025-0308
- EPSS 1.26%
- Veröffentlicht 18.01.2025 06:15:27
- Zuletzt bearbeitet 25.02.2025 22:14:17
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due...
CVE-2024-10528
- EPSS 0.11%
- Veröffentlicht 21.11.2024 11:15:19
- Zuletzt bearbeitet 21.02.2025 19:40:08
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_i...
CVE-2024-8520
- EPSS 0.26%
- Veröffentlicht 04.10.2024 05:15:11
- Zuletzt bearbeitet 08.10.2024 21:50:30
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or...
CVE-2024-8519
- EPSS 0.3%
- Veröffentlicht 04.10.2024 05:15:11
- Zuletzt bearbeitet 16.10.2024 14:06:04
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and i...
CVE-2024-2765
- EPSS 0.29%
- Veröffentlicht 02.05.2024 17:15:19
- Zuletzt bearbeitet 27.02.2025 16:24:20
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and i...
CVE-2024-1071
- EPSS 92.91%
- Veröffentlicht 13.03.2024 16:15:16
- Zuletzt bearbeitet 21.02.2025 19:33:40
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping...
CVE-2024-2123
- EPSS 41.29%
- Veröffentlicht 13.03.2024 10:15:08
- Zuletzt bearbeitet 21.02.2025 19:31:33
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8....
CVE-2023-31216
- EPSS 0.07%
- Veröffentlicht 17.07.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:38
Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.