cross-site scripting (XSS multipla) le vulnerabilità in base include / / UM-azioni-login.php in ""Ultimate Stati – Profilo utente & Membership"" plugin prima 2.0.28 per WordPress permettono aggressori remoti di inserire lo script Web arbitrario o HTML tramite il pulsante ""testo primario"" o il campo ""pulsante seconda testo"". |
https://wordpress.org/plugins/ultimate-member/#developers https://serhack.me/articles/ultimate-member-xss-security-issue https://wpvulndb.com/vulnerabilities/9615 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17866 |
Vulnerabilità: CVE-2018-17866
