CVE-2018-6944: XSS
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6944?
CVE-2018-6944 is a vulnerability in the UltimateMember plugin 2.0 for WordPress that allows for cross-site scripting due to improper input sanitization.
How severe is CVE-2018-6944?
CVE-2018-6944 has a severity rating of 6.1, which is considered medium.
How does CVE-2018-6944 affect UltimateMember plugin 2.0 for WordPress?
CVE-2018-6944 affects UltimateMember plugin 2.0 for WordPress by allowing attackers to exploit a cross-site scripting vulnerability.
What is the Common Weakness Enumeration (CWE) for CVE-2018-6944?
CVE-2018-6944 is associated with CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
How can I fix the CVE-2018-6944 vulnerability?
To fix the CVE-2018-6944 vulnerability, you should install the latest version of the UltimateMember plugin for WordPress, as it likely includes a patch for this vulnerability.