CVE-2019-14947: XSS
Published Aug 12, 2019
·Updated
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
Affected Software
1 affected component
ultimatemember Ultimate Member Wordpress<2.0.52
Event History
Aug 12, 2019
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-14947.
2
What is the severity of CVE-2019-14947?
The severity of CVE-2019-14947 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is the Ultimate Member plugin for WordPress versions up to and excluding 2.0.52.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix CVE-2019-14947?
To fix CVE-2019-14947, you should update the Ultimate Member plugin to version 2.0.52 or newer.