cleantalk
Vulnerabilities and Security Researches

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, CVE-2020-36170

CVE, Research URL

CVE-2020-36170

Published on
Jan 06, 2021
Research Description
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
Affected versions
max 2.1.13.
Status
vulnerable