CVE-2016-10872: XSS
Published Aug 12, 2019
·Updated
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
Affected Software
1 affected component
ultimatemember Ultimate Member Wordpress<1.3.40
Event History
Aug 12, 2019
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2016-10872.
2
What is the severity of CVE-2016-10872?
The severity of CVE-2016-10872 is medium (6.1).
3
Which software versions are affected by CVE-2016-10872?
The ultimate-member plugin versions up to and excluding 1.3.40 for WordPress are affected by CVE-2016-10872.
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for CVE-2016-10872 is CWE-79.
5
How can I fix the XSS vulnerability in the ultimate-member plugin?
To fix the XSS vulnerability, you should update the ultimate-member plugin to version 1.3.40 or newer.