Description
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1158)
Atlassian Jira Deserialization of Untrusted Data Vulnerability (CVE-2017-5983)
WordPress Plugin Powie's WHOIS Domain Check Cross-Site Scripting (0.9.31)
WordPress Plugin Polldaddy Polls & Ratings Cross-Site Request Forgery (2.0.20)
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33325)