First published: Mon May 14 2018(Updated: )
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-0585 is medium with a CVSS score of 5.4.
CVE-2018-0585 allows remote attackers to inject arbitrary web script or HTML into the Ultimate Member plugin.
The Ultimate Member plugin prior to version 2.0.4 is affected by CVE-2018-0585.
To fix CVE-2018-0585, you should update the Ultimate Member plugin to version 2.0.4 or later.
You can find more information about CVE-2018-0585 at the following references: [http://jvn.jp/en/jp/JVN28804532/index.html](http://jvn.jp/en/jp/JVN28804532/index.html), [https://wordpress.org/plugins/ultimate-member/#developers](https://wordpress.org/plugins/ultimate-member/#developers), [https://wpvulndb.com/vulnerabilities/9608](https://wpvulndb.com/vulnerabilities/9608).