Description
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
Remediation
References
Related Vulnerabilities
WordPress Plugin Permalink Manager Lite Cross-Site Request Forgery (2.2.20.1)
WordPress Plugin AmazonFeed Cross-Site Scripting (2.1)
WebLogic CVE-2016-0696 Vulnerability (CVE-2016-0696)
WordPress Plugin Lazy content Slider Cross-Site Request Forgery (3.4)
WordPress Plugin Image Gallery-Responsive Photo Gallery SQL Injection (1.8.9)