Description
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-3079 Vulnerability (CVE-2018-3079)
WordPress Plugin WP Smart Image II Cross-Site Scripting (0.2)
WordPress Plugin Job Manager Cross-Site Scripting (0.7.22)
WordPress Plugin WP Symposium Cross-Site Scripting (13.02)
ATutor Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3706)