CVE-2018-13136: XSS
Published Jul 4, 2018
·Updated
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Affected Software
1 affected component
ultimatemember Ultimate Member Wordpress<2.0.18
Event History
Jul 4, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-13136.
2
What is the severity of CVE-2018-13136?
The severity of CVE-2018-13136 is medium.
3
What is the affected software?
The affected software is the Ultimate Member plugin for WordPress before version 2.0.18.
4
What is the CWE ID associated with CVE-2018-13136?
The CWE ID associated with CVE-2018-13136 is CWE-79.
5
How can I fix CVE-2018-13136?
You can fix CVE-2018-13136 by updating the Ultimate Member plugin to version 2.0.18 or newer.