PT-2019-11675 · WordPress · Ultimate Member

Clément Cruchet

·

Published

2019-06-24

·

Updated

2024-03-05

·

CVE-2019-10271

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ultimate Member plugin version 2.39
Description An issue in the Ultimate Member plugin for WordPress allows unauthorized modification of user profiles and cover pictures. Once connected, an attacker can modify the profile and cover picture of any user, including those of privileged users. To exploit this, an attacker would need to intercept an upload-picture request and modify the user id parameter.
Recommendations For Ultimate Member plugin version 2.39, consider disabling the profile and cover picture modification functionality until a patch is available. Restrict access to the upload-picture request to minimize the risk of exploitation. Avoid using the user id parameter in the affected request until the issue is resolved.

Fix

Related Identifiers

CVE-2019-10271

Affected Products

Ultimate Member