The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wp_usermeta table.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1601 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wp_usermeta table. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ultimatemember
Ultimatemember ultimate Member |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ultimatemember
Ultimatemember ultimate Member |
Wed, 22 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 18 Jan 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wp_usermeta table. | |
| Title | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-22T14:19:41.702Z
Reserved: 2025-01-07T22:50:30.349Z
Link: CVE-2025-0318
Updated: 2025-01-22T14:19:22.573Z
Status : Analyzed
Published: 2025-01-18T06:15:28.017
Modified: 2025-02-25T22:09:05.680
Link: CVE-2025-0318
No data.
OpenCVE Enrichment
No data.
EUVD