Vulnerabilities > Ultimatemember > User Profile Membership > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-14 CVE-2018-0588 Path Traversal vulnerability in Ultimatemember User Profile & Membership
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
ultimatemember CWE-22
7.5
2018-04-23 CVE-2018-10233 Cross-Site Request Forgery (CSRF) vulnerability in Ultimatemember User Profile & Membership
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks.
network
low complexity
ultimatemember CWE-352
8.8