Ultimate Member <= 2.3.1 - Arbitrary Redirect
2022-04-29 00:00
Ruijie LiStrategic Overview
StatusPatched in 2.3.2
Affected PluginUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Affected Version
<= 2.3.1CVSS4.3Medium
CVE
CVE-2022-1209Vulnerability Overview
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
Technical Analysis
REMEDIATION: Update to version 2.3.2, or a newer patched version --- IDENTIFIER: CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C