Ultimate Member <= 1.3.83 - Shortcode Injection
2017-04-17 00:00
James GolovichStrategic Overview
StatusPatched in 1.3.84
Affected PluginUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Affected Version
<= 1.3.83CVSS9.8Critical
CVE
N/AVulnerability Overview
The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, and including, 1.3.83. This is due to 'ultimatemember_frontend_modal' AJAX action allowing for the execution of the 'do_shortcode()' function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Technical Analysis
REMEDIATION: Update to version 1.3.84, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C