CVE-2018-10234: XSS
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=umoptions§ion=account page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10234?
CVE-2018-10234 is an Authenticated Cross site Scripting vulnerability in the User Profile & Membership plugin before version 2.0.11 for WordPress.
How does CVE-2018-10234 affect the User Profile & Membership plugin?
CVE-2018-10234 allows authenticated users to execute malicious scripts through the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
What is the severity of CVE-2018-10234?
CVE-2018-10234 has a severity rating of medium with a CVSS score of 4.8.
How do I fix CVE-2018-10234?
To fix CVE-2018-10234, it is recommended to update the User Profile & Membership plugin to version 2.0.11 or later.
Where can I find more information about CVE-2018-10234?
You can find more information about CVE-2018-10234 on the GitHub page (https://github.com/RiieCco/write-ups/tree/master/CVE-2018-10234) and the official WordPress plugin page (https://wordpress.org/plugins/ultimate-member/#developers).