Description
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
Remediation
References
Related Vulnerabilities
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Cross-Site Scripting (7.9)
WordPress Plugin WP Editor SQL Injection (1.2.6.3)
WordPress Plugin Yandex Money button Cross-Site Scripting (2.3.3)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-13402)