CVE-2018-17866: XSS
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17866?
CVE-2018-17866 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML via the 'Primary button Text' or 'Second button text' field in the Ultimate Member - User Profile & Membership plugin before version 2.0.28 for WordPress.
How severe is CVE-2018-17866?
CVE-2018-17866 has a severity rating of medium (6.1).
How can the Ultimate Member - User Profile & Membership plugin be affected by CVE-2018-17866?
The Ultimate Member - User Profile & Membership plugin before version 2.0.28 for WordPress is affected by CVE-2018-17866, allowing remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities.
How can I fix CVE-2018-17866?
To fix CVE-2018-17866, it is recommended to update the Ultimate Member - User Profile & Membership plugin to version 2.0.28 or higher.
Where can I find more information about CVE-2018-17866?
You can find more information about CVE-2018-17866 at the following references: [1] [2] [3]