First published: Wed May 07 2025(Updated: )
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member allows Code Injection. This issue affects Ultimate Member: from n/a through 2.10.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <=2.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47691 is recognized as a critical vulnerability due to its potential for code injection.
To fix CVE-2025-47691, you should update the Ultimate Member plugin to at least version 2.10.4.
CVE-2025-47691 affects Ultimate Member versions up to and including 2.10.3.
CVE-2025-47691 is classified as a Code Injection vulnerability.
Users of Ultimate Member are at risk of attackers executing arbitrary code on their websites due to CVE-2025-47691.