First published: Fri Feb 16 2018(Updated: )
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6944 is a vulnerability in the UltimateMember plugin 2.0 for WordPress that allows for cross-site scripting due to improper input sanitization.
CVE-2018-6944 has a severity rating of 6.1, which is considered medium.
CVE-2018-6944 affects UltimateMember plugin 2.0 for WordPress by allowing attackers to exploit a cross-site scripting vulnerability.
CVE-2018-6944 is associated with CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix the CVE-2018-6944 vulnerability, you should install the latest version of the UltimateMember plugin for WordPress, as it likely includes a patch for this vulnerability.