CyberSec.Space Logo
Back to CVE Browser

CVE-2019-10673

HIGH
8.8
CVSS Severity Score
EPSS Score0.1040%
EPSS Percentile26.48th
PublishedApr 3, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.

Affected Platforms (CPE)

πŸ“¦
Ultimatemember

Ultimate Member

< 2.0.40

References & Advisories

Related Vulnerabilities