CVE-2018-6943: XSS
Published Feb 16, 2018
·Updated
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Affected Software
1 affected component
ultimatemember Ultimatemember Wordpress=2.0
Event History
Feb 16, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6943?
The severity of CVE-2018-6943 is medium (6.1).
2
How does the UltimateMember plugin 2.0 for WordPress get affected by CVE-2018-6943?
The UltimateMember plugin 2.0 for WordPress is affected by CVE-2018-6943 due to a cross-site scripting vulnerability.
3
What is the affected software version of CVE-2018-6943?
The affected software version of CVE-2018-6943 is UltimateMember plugin 2.0 for WordPress.
4
How can I mitigate the CVE-2018-6943 vulnerability?
To mitigate the CVE-2018-6943 vulnerability, upgrade to a fixed version of the UltimateMember plugin.