CVE-2020-36170: Medium severity ultimate member vulnerability
Published Jan 6, 2021
·Updated
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
Affected Software
1 affected component
ultimatemember Ultimate Member Wordpress<2.1.13
Event History
Jan 6, 2021
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for The Ultimate Member plugin?
The vulnerability ID for The Ultimate Member plugin is CVE-2020-36170.
2
What is the severity of CVE-2020-36170?
The severity of CVE-2020-36170 is medium with a severity value of 5.3.
3
What is the affected version of The Ultimate Member plugin?
The affected version of The Ultimate Member plugin is up to, but excluding, version 2.1.13.
4
What is the risk of the vulnerability in The Ultimate Member plugin?
The risk of the vulnerability in The Ultimate Member plugin is that it mishandles hidden name="timestamp" fields in forms.
5
Where can I find more information about The Ultimate Member plugin vulnerability?
You can find more information about The Ultimate Member plugin vulnerability on the WordPress plugins page.