CVE-2020-36155 – Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Meta
https://notcve.org/view.php?id=CVE-2020-36155
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access. Se detectó un problema en el plugin Ultimate Member versiones anteriores a 2.1.12 para WordPress, también se conoce como una Escalada de Privilegios No Autenticada por medio de User Meta. Un atacante podría suministrar un parámetro de matriz para metadatos confidenciales, tal y como el usuario meta de wp_capabilities que define el rol de un usuario. • https://wordpress.org/plugins/ultimate-member/#developers https://wpscan.com/vulnerability/cf13b0f8-5815-4d27-a276-5eff8985fc0b https://www.wordfence.com/blog/2020/11/critical-privilege-escalation-vulnerabilities-affect-100k-sites-using-ultimate-member-plugin • CWE-269: Improper Privilege Management •
CVE-2020-6859 – Ultimate Member <= 2.1.2 - Insecure Direct Object Reference
https://notcve.org/view.php?id=CVE-2020-6859
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image. Múltiples vulnerabilidades de Referencia a Objeto Directa y No Segura en el archivo include/core/class-files.php en el plugin Ultimate Member versiones hasta la versión 2.1.2 para WordPress, permiten a atacantes remotos cambiar los perfiles de otros usuarios y las fotos de portada por medio de un parámetro user_id modificado. Esto está relacionado con ajax_image_upload y ajax_resize_image. • https://github.com/ultimatemember/ultimatemember/blob/627bbb0fae81ac34c60b43f0867eadcf8e1bc523/includes/core/class-files.php#L269 https://github.com/ultimatemember/ultimatemember/blob/627bbb0fae81ac34c60b43f0867eadcf8e1bc523/includes/core/class-files.php#L310 https://github.com/ultimatemember/ultimatemember/commit/249682559012734a4f7d71f52609b2f301ea55b1 https://wordpress.org/plugins/ultimate-member/#developers https://wpvulndb.com/vulnerabilities/10041 • CWE-269: Improper Privilege Management CWE-639: Authorization Bypass Through User-Controlled Key •
CVE-2018-20965 – Ultimate Member <= 2.0.3 - Cross Site Scripting
https://notcve.org/view.php?id=CVE-2018-20965
The ultimate-member plugin before 2.0.4 for WordPress has XSS. El plugin ultimate-member antes de la versión 2.0.4 para WordPress tiene XSS. • https://wordpress.org/plugins/ultimate-member/#developers https://wpvulndb.com/vulnerabilities/9608 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-14945 – Ultimate Member <= 2.0.53 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-14945
The ultimate-member plugin before 2.0.54 for WordPress has XSS. El plugin ultimate-member antes de la versión 2.0.54 para WordPress tiene XSS. • https://wordpress.org/plugins/ultimate-member/#developers https://wpvulndb.com/vulnerabilities/9506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-14946 – Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-14946
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. El plugin ultimate-member anterior a la versión 2.0.52 para WordPress tiene XSS relacionado con las operaciones de creación y edición de roles de mensajería unificada. • https://wordpress.org/plugins/ultimate-member/#developers https://wpvulndb.com/vulnerabilities/9449 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •