The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2022-05-10T19:34:42
Updated: 2024-08-02T23:55:24.204Z
Reserved: 2022-04-01T00:00:00
Link: CVE-2022-1209
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-05-10T20:15:08.407
Modified: 2024-11-21T06:40:15.607
Link: CVE-2022-1209
Redhat
No data.