Description The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. Remediation References CVE-2015-9304 Related Vulnerabilities Joomla! Core Multiple Vulnerabilities (1.5.0 - 3.8.11) WordPress Plugin WordPress Simple Shop Cross-Site Scripting (1.2) WordPress Plugin Portfolio Responsive Gallery SQL Injection (1.1.7) WordPress 6.0.x Multiple Vulnerabilities (6.0 - 6.0.5) MySQL CVE-2015-0433 Vulnerability (CVE-2015-0433) Severity Medium Classification CVE-2015-9304 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities