MEDIUM
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter
Published Jan 13, 2020
5.3
MEDIUMCVSS 3.1
EPSS 2.17%
Description
Affected products
Remediation
References (6)
Change history (0)
No recorded changes yet.