CVE-2022-1209 Information
Jun 07, 2022
cve
Description
The Ultimate Member plugin for WordPress is vulnerable to open redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page which makes it possible for attackers to redirect unsuspecting victims in versions up to and including 2.3.1 granted the victim clicks on a social icon on a user’s profile page.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/ultimatemember/ultimatemember/issues/989 https://github.com/ultimatemember/ultimatemember/pull/990 https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1209 https://github.com/H4de5-7/vulnerabilities/blob/main/Ultimate%20Member%20%3C%3D%202.3.1%20-%20Open%20Redirect.md
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: