CVE-2020-36156
- EPSS 0.93%
- Veröffentlicht 04.01.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:50
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to...
CVE-2020-36155
- EPSS 61.44%
- Veröffentlicht 04.01.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:49
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that ...
CVE-2020-6859
- EPSS 1.14%
- Veröffentlicht 13.01.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:18
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parame...
CVE-2019-14947
- EPSS 0.58%
- Veröffentlicht 12.08.2019 16:15:15
- Zuletzt bearbeitet 21.11.2024 04:27:44
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
CVE-2019-14946
- EPSS 0.38%
- Veröffentlicht 12.08.2019 16:15:15
- Zuletzt bearbeitet 21.11.2024 04:27:44
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
CVE-2019-14945
- EPSS 0.58%
- Veröffentlicht 12.08.2019 16:15:15
- Zuletzt bearbeitet 21.11.2024 04:27:44
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
CVE-2018-20965
- EPSS 0.35%
- Veröffentlicht 12.08.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:02:34
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
CVE-2016-10872
- EPSS 0.31%
- Veröffentlicht 12.08.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 02:44:57
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVE-2015-9304
- EPSS 0.26%
- Veröffentlicht 12.08.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 02:40:17
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
CVE-2019-10271
- EPSS 0.22%
- Veröffentlicht 24.06.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:18:47
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the...