First published: Fri Feb 16 2018(Updated: )
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-6943 is medium (6.1).
The UltimateMember plugin 2.0 for WordPress is affected by CVE-2018-6943 due to a cross-site scripting vulnerability.
The affected software version of CVE-2018-6943 is UltimateMember plugin 2.0 for WordPress.
To mitigate the CVE-2018-6943 vulnerability, upgrade to a fixed version of the UltimateMember plugin.