QID 731271

Date Published: 2024-03-19

QID 731271: WordPress Plugin Ultimate Member Cross-Site Scripting (XSS) Vulnerability

Ultimate Member user profile and membership plugin for WordPress. The plugin allows you to add beautiful user profiles to your site and is perfect for creating advanced online communities and membership sites.

The Ultimate Member User Profile Registration Login Member Directory Content Restriction and Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to and including 2.8.3 due to insufficient input sanitization and output escaping.

Affected Versions:
WordPress Plugin Ultimate Member versions prior to 2.8.4

QID Detection Logic:
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Ultimate Member WordPress plugin.

Successful exploitation of this vulnerability may allow unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Ultimate Member 2.8.4 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731271

    Software Advisories
    Advisory ID Software Component Link
    Ultimate Member Plugin Release URL Logo wordpress.org/plugins/ultimate-member/#developers