JVN#28804532Third-party advisory
http://jvn.jp/en/jp/JVN28804532/index.html CVE-2018-0590
MEDIUM
Record summary
CVE-2018-0590 has a selected CVSS score of 4.3 (medium).
Description
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ultimate MemberBrowse Ultimate Member / Ultimate Member | CVE List | prior to version 2.0.4 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0590 wordpress.orgConfirmation
https://wordpress.org/plugins/ultimate-member wpvulndb.com
https://wpvulndb.com/vulnerabilities/9608