Description
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Remediation
References
Related Vulnerabilities
WordPress Plugin Images Slideshow by 2J-Image Slider Unspecified Vulnerability (1.2.15)
MySQL CVE-2013-0384 Vulnerability (CVE-2013-0384)
Ruby on Rails Improper Access Control Vulnerability (CVE-2015-7577)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1570)