Input validation vulnerability in Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.5.0

The Ultimate Member plugin for WordPress is vulnerable to a security risk called Remote Code Execution. This means that someone with malicious intent and access to the plugin can run code on the server. This vulnerability affects versions up to and including 2.5.0 of the plugin. It occurs when the plugin’s “”populate_dropdown_options”” function accepts user-supplied input and passes it through a function called “”call_user_func””. This allows hackers to execute code on the server

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.