Input validation vulnerability in Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.0.46

The Ultimate Member plugin for WordPress has a security vulnerability in versions up to, and including, 2.0.45. This vulnerability allows an attacker with administrative level access to inject malicious web scripts into pages. These scripts will be executed whenever a user visits the page and can be used to do damage. This vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.