Vulnerabilities > Ultimatemember > Ultimate Member > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-17 | CVE-2023-31216 | Cross-Site Request Forgery (CSRF) vulnerability in Ultimatemember Ultimate Member Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions. | 8.8 |
2022-11-29 | CVE-2022-3383 | Unspecified vulnerability in Ultimatemember Ultimate Member The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). | 7.2 |
2022-11-29 | CVE-2022-3384 | Unspecified vulnerability in Ultimatemember Ultimate Member The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). | 7.2 |
2022-11-13 | CVE-2022-3966 | Path Traversal vulnerability in Ultimatemember Ultimate Member A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. | 7.5 |
2021-01-04 | CVE-2020-36157 | Improper Privilege Management vulnerability in Ultimatemember Ultimate Member An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. | 7.5 |
2021-01-04 | CVE-2020-36155 | Improper Privilege Management vulnerability in Ultimatemember Ultimate Member An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. | 7.5 |