Input validation vulnerability in Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.0.32

The Ultimate Member plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery. This is a vulnerability that exists in versions up to 2.0.32 of the plugin. It is caused by either missing or incorrectly implemented security measures, known as nonce validation, on several functions. This vulnerability allows unauthenticated attackers to take control of a website by tricking an administrator into clicking on a malicious link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.