WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-10872 - Vulnerability Database

WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2016-10872

Medium
Reference: CVE-2016-10872
Title: WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.