Description
WordPress Plugin Ultimate Membership Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently generate an export containing PII (username, email address, IP address, User-Agent and so on), as well as generate authentication links by suppling an ID or Username. WordPress Plugin Ultimate Membership Pro version 8.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.6.1 or latest
References
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (4.0.2)
WordPress Plugin Gmedia Photo Gallery Cross-Site Scripting (0.9.3)
WordPress Plugin DB Toolkit 'uploadify.php' Arbitrary File Upload (0.1.10)
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more Cross-Site Scripting (2.5.2.1)
WordPress Plugin Responsive Menu-Create Mobile-Friendly Menu Multiple Vulnerabilities (3.1.3)