Vulnerabilities > Ultimatemember > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-23 CVE-2018-10233 Cross-Site Request Forgery (CSRF) vulnerability in Ultimatemember User Profile & Membership
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks.
network
low complexity
ultimatemember CWE-352
8.8