Skip to main content

Vendor/product archive

ultimatemember / user_profile_&_membership CVEs

Beta · best-effort

7 CVEs tagged to ultimatemember / user_profile_&_membership0 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2018-0590

Published May 14, 2018

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0589

Published May 14, 2018

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0588

Published May 14, 2018

Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0587

Published May 14, 2018

Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0586

Published May 14, 2018

Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10234

Published Apr 23, 2018

Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/ad…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10233

Published Apr 23, 2018

The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1