CVE-2018-0590
Ultimate Member < 2.0.4 - Insecure Direct Object Reference
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
El plugin Ultimate Member en versiones anteriores a la 2.0.4 para WordPress permite que los atacantes remotos autenticados omitan la restricción de acceso para modificar los perfiles de los otros usuarios mediante vectores sin especificar.
The Ultimate Member plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions prior to version 2.0.4. This is due to bypass access restriction via unspecified vectors. This makes it possible for authenticated attackers to modify the other users profiles via unspecified vectors.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-05-10 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://jvn.jp/en/jp/JVN28804532/index.html | Third Party Advisory | |
https://wordpress.org/plugins/ultimate-member/#developers | Release Notes | |
https://wpvulndb.com/vulnerabilities/9608 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimatemember Search vendor "Ultimatemember" | User Profile \& Membership Search vendor "Ultimatemember" for product "User Profile \& Membership" | < 2.0.4 Search vendor "Ultimatemember" for product "User Profile \& Membership" and version " < 2.0.4" | wordpress |
Affected
|