First published: Wed Jul 04 2018(Updated: )
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-13136.
The severity of CVE-2018-13136 is medium.
The affected software is the Ultimate Member plugin for WordPress before version 2.0.18.
The CWE ID associated with CVE-2018-13136 is CWE-79.
You can fix CVE-2018-13136 by updating the Ultimate Member plugin to version 2.0.18 or newer.