Advertisement






Ultimate Member 2.39 Unauthorized profile modification

CVE Category Price Severity
CVE-2019-10271 CWE-200 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2019-06-18
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019060120

Below is a copy:

Ultimate Member 2.39 Unauthorized profile modification
#### [CVE-2019-10271] Ultimate Member 2.39 Unauthorized profile modification
 
#### Description ####
 
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. As a connected and authenticated user it is possible to modify the profile and cover picture of any user. It is also possible to modify the profiles and cover pictures of privileged users as admin user.
 
#### Timeline (dd/mm/yyyy) ####
 ++ 12/03/2019 : Initial discovery 
 ++ 13/03/2019 : First contact attempt (email) 
 ++ 13/03/2019 : Response from editor
 ++ 26/03/2019 : Technical details sent to the editor 
 ++ 26/03/2019 : Reply: fix planned for release 2.40
 ++ 15/06/2019 : Release of the advisory 
 
#### Fixes Upgrade to Ultimate Member 2.40 ####
 
#### Affected versions ####
 ++ Versions up to 2.39
 
#### Credits #### 
 ++ Clment CRUCHET <[email protected]>
 
####  Reference #### 
 ++ https://ultimatemember.com/
 

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum