First published: Mon Aug 12 2019(Updated: )
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-14947.
The severity of CVE-2019-14947 is medium with a CVSS score of 5.4.
The affected software is the Ultimate Member plugin for WordPress versions up to and excluding 2.0.52.
The CWE ID for this vulnerability is CWE-79.
To fix CVE-2019-14947, you should update the Ultimate Member plugin to version 2.0.52 or newer.