SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10271

It allows unauthorized profile and cover picture modification.

MEDIUM 4.3EPSS 0.86%

Does this matter?

Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such a modification, one first needs to (for example) intercept an upload-picture request and modify the user_id parameter.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.86% probability · 56th percentile
CISA KEV
Not listed
Affected
ultimatemember/ultimate member
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.