Description
WordPress Plugin Ultimate Membership Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently generate an export containing PII (username, email address, IP address, User-Agent and so on), as well as generate authentication links by suppling an ID or Username. WordPress Plugin Ultimate Membership Pro version 8.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.6.1 or latest
References
Related Vulnerabilities
WordPress Plugin WP Fastest Cache Local File Inclusion (0.8.5.9)
WordPress Plugin Bookshelf Cross-Site Scripting (2.0.4)
Atlassian Jira CVE-2021-26075 Vulnerability (CVE-2021-26075)
WordPress Plugin Arigato Autoresponder and Newsletter Remote Code Execution (2.5.1.9)
WordPress Plugin WP Instagram-Best Instagram Feeds Cross-Site Scripting (1.0.19)