cleantalk
Vulnerabilities and Security Researches

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, CVE-2018-10233

CVE, Research URL

CVE-2018-10233

Published on
Apr 23, 2018
Research Description
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
Affected versions
max 2.0.7.
Status
vulnerable