Description
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2016-0671 Vulnerability (CVE-2016-0671)
MySQL CVE-2018-2766 Vulnerability (CVE-2018-2766)
SharePoint NULL Pointer Dereference Vulnerability (CVE-2020-1069)
Drupal Core 4.7.x HTTP Response Splitting (4.7.0 - 4.7.7)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22881)