Input validation vulnerability in Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 1.2.997

The Ultimate Member plugin for WordPress is vulnerable to a type of cyber attack called Reflected Cross-Site Scripting. This attack can be used to inject malicious code into web pages. It affects versions 1.2.98 through 1.2.997 of the plugin and is caused by inadequate safeguards against the malicious code. If a user is tricked into clicking on a link, the malicious code will be activated. To protect your website, make sure you are using the latest version of the Ultimate Member plugin for WordPress. If you have an older version, update it as soon as possible.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.