WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-13136 - Vulnerability Database
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-13136
Medium
Reference:
CVE-2018-13136
Title:
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.