CVE-2024-8519

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 16, 2024
CWE ID 79

Summary

CVE-2024-8519 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Ultimate Member plugin for WordPress. Versions up to and including 2.8.6 are susceptible to this issue. The 'um_loggedin' shortcode, used for displaying content based on user login status, does not adequately sanitize or escape user-supplied attributes. This oversight allows authenticated attackers with contributor-level access or higher to inject malicious scripts. These scripts will execute whenever an affected user accesses a manipulated page.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ultimatemember Ultimate Member

Affected Vendors

  • Ultimatemember