CVE-2018-10233: CSRF
Published Apr 23, 2018
·Updated
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
Affected Software
1 affected component
ultimatemember User Profile \& Membership Wordpress<2.0.7
Event History
Apr 23, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-10233.
2
What is the severity of CVE-2018-10233?
CVE-2018-10233 has a severity score of 8.8 (high).
3
What is the affected software?
The affected software is the User Profile & Membership plugin version up to 2.0.7 for WordPress.
4
What is the issue with the User Profile & Membership plugin?
The User Profile & Membership plugin does not have any implemented mitigations against cross-site request forgery (CSRF) attacks.
5
How can I fix CVE-2018-10233?
To fix CVE-2018-10233, it is recommended to update the User Profile & Membership plugin to version 2.0.7 or higher.