ZeroHour

CVE-2022-1209

PoC ×2
CVSS 3.1
5.4 medium
EPSS
<1%p52
Published
()
Modified
Description

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

Vendors
ultimatemember
Products
ultimate member
Ecosystems
WordPress
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.