Description
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.6.11)
Ruby on Rails Deserialization of Untrusted Data Vulnerability (CVE-2018-16476)
phpBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2002-2346)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-10678)