Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset any users password to an arbitrary value. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.3.75 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 1.3.77 or latest
References
Related Vulnerabilities
WordPress Plugin Search Engine Unspecified Vulnerability (0.5.8)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4589)
WordPress Plugin Sender by BestWebSoft Multiple Vulnerabilities (0.7)
WordPress Plugin Abandoned Cart Recovery for WooCommerce Cross-Site Request Forgery (1.0.4)