Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.6 or latest
References
Related Vulnerabilities
XWiki Incorrect Authorization Vulnerability (CVE-2024-38369)
MySQL CVE-2014-4240 Vulnerability (CVE-2014-4240)
WordPress Plugin Page Restrict Open Redirect (2.2.3)
PHP Address Book Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-2778)
WordPress Plugin Kindeditor For WordPress Cross-Site Scripting (1.3.3)