Filtered by vendor Ultimatemember
Subscribe
Filtered by product User Profile \& Membership
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-0588 | 1 Ultimatemember | 1 User Profile \& Membership | 2019-11-20 | 6.4 MEDIUM | 7.5 HIGH |
| Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. | |||||
| CVE-2018-10233 | 1 Ultimatemember | 1 User Profile \& Membership | 2019-10-06 | 6.8 MEDIUM | 8.8 HIGH |
| The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin. | |||||
