Input validation vulnerability in Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.9.2

The Ultimate Member plugin for WordPress has a security vulnerability that allows attackers to manipulate filenames and inject additional SQL queries, potentially accessing sensitive information from the database. This can only happen if the attacker has access to upload files and manage filenames through a third-party plugin, like a File Manager. The risk of this vulnerability is low, as it requires specific actions from a user to be successfully exploited.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.