CVE-2022-1208: Ultimate Member <= 2.3.2 - Stored Cross-Site Scripting
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This affects versions up to, and including, 2.3.2. Please note this issue was only partially fixed in version 2.3.2.
Other sources
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This affects versions up to, and including, 2.3.2. Please note this issue was partially fixed in version 2.3.2 then subsequently fully patched in version 2.3.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1208?
CVE-2022-1208 is a vulnerability in the Ultimate Member plugin for WordPress that allows for Stored Cross-Site Scripting (XSS) attacks via the Biography field on user profile pages.
How does CVE-2022-1208 affect Ultimate Member plugin?
CVE-2022-1208 affects the Ultimate Member plugin for WordPress versions up to and including 2.3.2.
What is the severity of CVE-2022-1208?
CVE-2022-1208 has a severity rating of medium.
How can I fix CVE-2022-1208?
To fix CVE-2022-1208, it is recommended to update the Ultimate Member plugin to the latest version available.
Where can I find more information about CVE-2022-1208?
You can find more information about CVE-2022-1208 on the following references: [Link 1](https://github.com/H4de5-7/vulnerabilities/blob/main/Ultimate%20Member%20%3C%3D%202.3.1%20-%20Stored%20Cross-Site%20Scripting.md), [Link 2](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2735896%40ultimate-member&new=2735896%40ultimate-member&sfp_email=&sfph_mail=), [Link 3](https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1208)