PT-2019-11675 · WordPress · Ultimate Member
Clément Cruchet
·
Published
2019-06-24
·
Updated
2024-03-05
·
CVE-2019-10271
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ultimate Member plugin version 2.39
Description
An issue in the Ultimate Member plugin for WordPress allows unauthorized modification of user profiles and cover pictures. Once connected, an attacker can modify the profile and cover picture of any user, including those of privileged users. To exploit this, an attacker would need to intercept an upload-picture request and modify the
user id parameter.Recommendations
For Ultimate Member plugin version 2.39, consider disabling the profile and cover picture modification functionality until a patch is available. Restrict access to the upload-picture request to minimize the risk of exploitation. Avoid using the
user id parameter in the affected request until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ultimate Member