CVE-2018-0589: Medium severity ultimate member vulnerability
Published May 14, 2018
·Updated
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
Affected Software
1 affected component
ultimatemember User Profile \& Membership Wordpress<2.0.4
Event History
May 14, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-0589.
2
What is the severity of CVE-2018-0589?
The severity of CVE-2018-0589 is medium with a CVSS score of 4.3.
3
How can an attacker exploit this vulnerability?
Remote authenticated attackers can bypass access restriction to add a new form in the 'Forms' page of the Ultimate Member plugin.
4
Which version of the Ultimate Member plugin is affected by this vulnerability?
The Ultimate Member plugin prior to version 2.0.4 is affected by this vulnerability.
5
How can I fix CVE-2018-0589?
Update the Ultimate Member plugin to version 2.0.4 or later to fix this vulnerability.