Description
WordPress Plugin Ultimate Membership Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently generate an export containing PII (username, email address, IP address, User-Agent and so on), as well as generate authentication links by suppling an ID or Username. WordPress Plugin Ultimate Membership Pro version 8.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.6.1 or latest
References
Related Vulnerabilities
WordPress Plugin Plugmatter Pricing Table Cross-Site Scripting (1.0.32)
WordPress Plugin Rate my Post-WP Rating System Cross-Site Scripting (3.3.8)
Oracle Application Server CVE-2009-0994 Vulnerability (CVE-2009-0994)
WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder Security Bypass (7.8.7)