First published: Mon Apr 23 2018(Updated: )
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10234 is an Authenticated Cross site Scripting vulnerability in the User Profile & Membership plugin before version 2.0.11 for WordPress.
CVE-2018-10234 allows authenticated users to execute malicious scripts through the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
CVE-2018-10234 has a severity rating of medium with a CVSS score of 4.8.
To fix CVE-2018-10234, it is recommended to update the User Profile & Membership plugin to version 2.0.11 or later.
You can find more information about CVE-2018-10234 on the GitHub page (https://github.com/RiieCco/write-ups/tree/master/CVE-2018-10234) and the official WordPress plugin page (https://wordpress.org/plugins/ultimate-member/#developers).