Ultimate Member <= 2.1.2 - Insecure Direct Object Reference
2020-01-13 00:00
AnonymousStrategic Overview
StatusPatched in 2.1.3
Affected PluginUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Affected Version
< 2.1.3CVSS5.3Medium
CVE
CVE-2020-6859Vulnerability Overview
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
Technical Analysis
REMEDIATION: Update to version 2.1.3, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C