Ultimate Member <= 2.1.6 - Open Redirect
2020-07-23 00:00
tonykoStrategic Overview
StatusPatched in 2.1.7
Affected PluginUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Affected Version
< 2.1.7CVSS6.1Medium
CVE
N/AVulnerability Overview
The Ultimate Member plugin for WordPress is vulnerable to open redirects in versions up to, and including, 2.1.6 This is due to insufficient redirect location validation which makes it possible for unauthenticated attackers to trick victims into accessing malicious sites granted they can trick the victim into performing an action such as clicking on a link.
Technical Analysis
REMEDIATION: Update to version 2.1.7, or a newer patched version --- IDENTIFIER: CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C