First published: Mon Aug 12 2019(Updated: )
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <1.3.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9304 is a vulnerability found in the ultimate-member plugin before version 1.3.18 for WordPress.
The severity level of CVE-2015-9304 is medium.
CVE-2015-9304 affects WordPress through the ultimate-member plugin version 1.3.18 and below.
CVE-2015-9304 belongs to the CWE category 79: Cross-Site Scripting (XSS).
To fix the CVE-2015-9304 vulnerability, update the ultimate-member plugin to version 1.3.18 or later.