First published: Tue Oct 09 2018(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17866 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML via the 'Primary button Text' or 'Second button text' field in the Ultimate Member - User Profile & Membership plugin before version 2.0.28 for WordPress.
CVE-2018-17866 has a severity rating of medium (6.1).
The Ultimate Member - User Profile & Membership plugin before version 2.0.28 for WordPress is affected by CVE-2018-17866, allowing remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities.
To fix CVE-2018-17866, it is recommended to update the Ultimate Member - User Profile & Membership plugin to version 2.0.28 or higher.
You can find more information about CVE-2018-17866 at the following references: [1] [2] [3]