Description
WordPress Plugin Ultimate Member-User Profile, User Registration, Login & Membership is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change other users' profiles and cover photos. WordPress Plugin Ultimate Member-User Profile, User Registration, Login & Membership version 2.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.3 or latest
References
Related Vulnerabilities
WordPress Plugin Gallery-Responsive Photo and Video Gallery by Limb Cross-Site Scripting (1.3.2)
WordPress Plugin External 'Video for Everybody' Cross-Site Scripting (2.0)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.1.4)
WordPress Plugin WP Table Builder-WordPress Table Security Bypass (1.3.15)