CVE-2018-10233
23.04.2018, 14:29
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
Vendor | Product | Version |
---|---|---|
ultimatemember | user_profile_\&_membership | 𝑥 < 2.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References