The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative capabilities, to execute code on the server.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-23T20:34:17.159Z
Reserved: 2022-09-30T19:32:01.065Z
Link: CVE-2022-3383
Updated: 2024-08-03T01:07:06.541Z
Status : Modified
Published: 2022-11-29T21:15:10.987
Modified: 2024-11-21T07:19:24.927
Link: CVE-2022-3383
No data.
OpenCVE Enrichment
No data.
Weaknesses