Vulnerabilities > Ultimatemember > Forumwp

DATE CVE VULNERABILITY TITLE RISK
2024-09-06 CVE-2024-8428 Authorization Bypass Through User-Controlled Key vulnerability in Ultimatemember Forumwp
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key.
network
low complexity
ultimatemember CWE-639
8.8