QID 731205
Date Published: 2024-02-28
QID 731205: WordPress Plugin Ultimate Member Unauthenticated SQL Injection Vulnerability
Ultimate Member user profile and membership plugin for WordPress. The plugin allows you to add beautiful user profiles to your site and is perfect for creating advanced online communities and membership sites.
This plugin is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
Affected Versions:
WordPress Plugin Ultimate Member versions from 2.1.3 prior to 2.8.3
QID Detection Logic:
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Ultimate Member WordPress plugin.
Successful exploitation of this vulnerability may allow unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Ultimate Member Plugin Release Notes -
wordpress.org/plugins/ultimate-member/#developers
CVEs related to QID 731205
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ultimate Member Plugin Release Notes |
|