Output validation vulnerability in WP User Manager – User Profile Builder & Membership 2.9.12

The User Manager plugin for WordPress has a security issue that allows attackers to inject malicious code into the system. This vulnerability affects versions up to 2.9.12 and can be exploited by authenticated attackers with subscriber-level access or higher. There is no known way to protect against this issue, but if the attacker has installed an additional plugin or theme on the system, they may be able to delete files, access sensitive information, or execute code.

Detected in:

WP User Manager – User Profile Builder & Membership open vulnerable versions: >= * <= 2.9.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.