Description
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-3368)
WordPress Plugin RSS Feed Widget Cross-Site Scripting (2.8.0)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.8.2)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-0010)
WordPress Plugin Event Organiser Cross-Site Scripting (2.12.4)