Description
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Information Disclosure (4.5.2)
Jboss EAP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-7464)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (3.2.6.8)
Joomla Session Fixation Vulnerability (CVE-2010-1434)
WordPress Plugin ShareThis Dashboard for Google Analytics Cross-Site Scripting (2.5.1)