Description
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
Remediation
References
Related Vulnerabilities
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2100)
WordPress Plugin Wordspew 'id' Parameter SQL Injection (1.16)
MySQL CVE-2013-3806 Vulnerability (CVE-2013-3806)
MyBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-2334)
WordPress Plugin Timed Popup Cross-Site Request Forgery (1.3)