cleantalk
Vulnerabilities and Security Researches

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, CVE-2018-13136

CVE, Research URL

CVE-2018-13136

Published on
Jul 04, 2018
Research Description
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Affected versions
max 2.0.18.
Status
vulnerable