Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total24
Critical2
High7
Medium15
Reset
Showing 21-24 of 24 records
Threat Entry Updated 2024-11-21

CVE-2023-3460 - Ultimate Member Plugin

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

PLUGIN Ultimate Member

CVE-2023-3460

CRITICAL CVSS 9.8 2023-07-04
Threat Entry Updated 2024-11-21

CVE-2022-1208 - Ultimate Member Plugin

The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This affects versions up to, and including, 2.3.2. Please note this issue was only partially fixed in version 2.3.2.

PLUGIN Ultimate Member

CVE-2022-1208

MEDIUM CVSS 6.4 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2022-1209 - Ultimate Member Plugin

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

PLUGIN Ultimate Member

CVE-2022-1209

MEDIUM CVSS 4.3 2022-05-10
Threat Entry Updated 2024-11-21

CVE-2021-24306 - Ultimate Member Plugin

The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link.

PLUGIN Ultimate Member

CVE-2021-24306

MEDIUM CVSS 5.4 2021-05-24
Scroll to top