CVE-2015-9304: XSS
Published Aug 12, 2019
·Updated
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
Affected Software
1 affected component
ultimatemember Ultimate Member Wordpress<1.3.18
Event History
Aug 12, 2019
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID CVE-2015-9304?
CVE-2015-9304 is a vulnerability found in the ultimate-member plugin before version 1.3.18 for WordPress.
2
What is the severity level of CVE-2015-9304?
The severity level of CVE-2015-9304 is medium.
3
How does CVE-2015-9304 affect WordPress?
CVE-2015-9304 affects WordPress through the ultimate-member plugin version 1.3.18 and below.
4
What is the CWE category of CVE-2015-9304?
CVE-2015-9304 belongs to the CWE category 79: Cross-Site Scripting (XSS).
5
How can I fix the CVE-2015-9304 vulnerability?
To fix the CVE-2015-9304 vulnerability, update the ultimate-member plugin to version 1.3.18 or later.