Description The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. Remediation References CVE-2019-14947 Related Vulnerabilities WordPress Plugin Nmedia MailChimp Widget 'abs_path' Parameter Remote File Include (3.1) WordPress Plugin RSS for Yandex Turbo Cross-Site Scripting (1.29) XWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-29512) WordPress Plugin Loco Translate Unspecified Vulnerability (2.5.4) WordPress Plugin PWA for WP & AMP Unspecified Vulnerability (1.0.8) Severity Medium Classification CVE-2019-14947 CWE-707 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities