CVE-2018-0585: XSS
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0585?
The severity of CVE-2018-0585 is medium with a CVSS score of 5.4.
How does CVE-2018-0585 affect the Ultimate Member plugin for WordPress?
CVE-2018-0585 allows remote attackers to inject arbitrary web script or HTML into the Ultimate Member plugin.
Which versions of the Ultimate Member plugin for WordPress are affected by CVE-2018-0585?
The Ultimate Member plugin prior to version 2.0.4 is affected by CVE-2018-0585.
How can I fix CVE-2018-0585?
To fix CVE-2018-0585, you should update the Ultimate Member plugin to version 2.0.4 or later.
Where can I find more information about CVE-2018-0585?
You can find more information about CVE-2018-0585 at the following references: [http://jvn.jp/en/jp/JVN28804532/index.html](http://jvn.jp/en/jp/JVN28804532/index.html), [https://wordpress.org/plugins/ultimate-member/#developers](https://wordpress.org/plugins/ultimate-member/#developers), [https://wpvulndb.com/vulnerabilities/9608](https://wpvulndb.com/vulnerabilities/9608).