Input validation vulnerability in Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin 1.4.36

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin for WordPress had a security flaw in versions up to and including 1.4.35. This flaw allowed attackers with subscriber-level permissions or higher to access and extract sensitive information from the database by using a certain parameter called ‘cate_id’ in a malicious way. This was possible because the parameter was not properly secured and the existing SQL query was not prepared in a secure way.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.