CVE-2015-8354: XSS
Published Sep 11, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the refer parameter to wp-admin/users.php.
Affected Software
1 affected component
ultimatemember Ultimate Member Wordpress<=1.3.28
Event History
Sep 11, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8354?
CVE-2015-8354 has a medium severity level due to the potential for remote attackers to execute malicious scripts.
2
How do I fix CVE-2015-8354?
To fix CVE-2015-8354, update the Ultimate Member plugin to version 1.3.29 or later.
3
What type of vulnerability is CVE-2015-8354?
CVE-2015-8354 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2015-8354?
CVE-2015-8354 affects users of the Ultimate Member plugin for WordPress prior to version 1.3.29.
5
What can attackers achieve with CVE-2015-8354?
Attackers can inject arbitrary web scripts or HTML via the _refer parameter in wp-admin/users.php.