VulnerabilityModified
CVE-2019-10271
It allows unauthorized profile and cover picture modification.
MEDIUM 4.3EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such a modification, one first needs to (for example) intercept an upload-picture request and modify the user_id parameter.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.86% probability · 56th percentile
- CISA KEV
- Not listed
- Affected
- ultimatemember/ultimate member
- Source
- cve@mitre.org
References
- https://cxsecurity.com/issue/WLB-2019060120Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019060120Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.