First published: Mon Jul 17 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <=2.6.0 |
Update to 2.6.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31216 is a Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin versions <= 2.6.0.
CVE-2023-31216 has a severity rating of 8.8, which is considered high.
The Ultimate Member plugin versions up to and including 2.6.0 are affected by CVE-2023-31216.
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into submitting a malicious request, often through social engineering or exploiting vulnerabilities in a trusted website.
To fix CVE-2023-31216, upgrade to a version of the Ultimate Member plugin that is higher than 2.6.0.