First published: Tue May 10 2022(Updated: )
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <=2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1209 is a vulnerability in the Ultimate Member plugin for WordPress that allows for open redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page.
The severity of CVE-2022-1209 is medium, with a CVSS score of 5.4.
CVE-2022-1209 affects the Ultimate Member plugin versions up to and including 2.3.1.
The impact of CVE-2022-1209 is that attackers can redirect unsuspecting victims to malicious websites by exploiting the open redirect vulnerability.
To fix CVE-2022-1209, it is recommended to update the Ultimate Member plugin to the latest version available.