Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.6 or latest
References
Related Vulnerabilities
Joomla Improper Input Validation Vulnerability (CVE-2018-12712)
WordPress Plugin Ultimate Maps by Supsystic SQL Injection (1.1.12)
PHP Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2010-4657)
Oracle Application Server Other Vulnerability (CVE-2002-0842)
phpBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-6506)