Vulnerabilities > Ultimatemember > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-13 CVE-2020-6859 Authorization Bypass Through User-Controlled Key vulnerability in Ultimatemember Ultimate Member
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter.
network
low complexity
ultimatemember CWE-639
5.3
2019-08-12 CVE-2019-14947 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
network
low complexity
ultimatemember CWE-79
5.4
2019-08-12 CVE-2019-14946 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
network
low complexity
ultimatemember CWE-79
5.4
2019-08-12 CVE-2019-14945 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
network
low complexity
ultimatemember CWE-79
5.4
2019-08-12 CVE-2018-20965 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
network
low complexity
ultimatemember CWE-79
6.1
2019-08-12 CVE-2016-10872 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
network
low complexity
ultimatemember CWE-79
6.1
2019-08-12 CVE-2015-9304 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
network
low complexity
ultimatemember CWE-79
6.1
2019-06-24 CVE-2019-10271 Unspecified vulnerability in Ultimatemember Ultimate Member
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress.
network
low complexity
ultimatemember
4.3
2018-10-09 CVE-2018-17866 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
network
low complexity
ultimatemember CWE-79
6.1
2018-07-04 CVE-2018-13136 Cross-site Scripting vulnerability in Ultimatemember Ultimate Member
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
network
low complexity
ultimatemember CWE-79
6.1