CVE-2024-8519

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The easiest way to create powerful online communities and beautiful user profiles with WordPress
GitHubGitHub
262
<h4>User Profile &amp; Membership Plugin for WordPress</h4> <p>The ultimate user profile &amp; membership plugin for WordPress. The plugin makes it a breeze for users to sign-up and become members of your website. The plugin allows you to add beautiful user profiles to your site and is designed for creating advanced online communities and membership sites. Lightweight and highly extendible, Ultimate Member will enable you to create almost any type of site where users can join and become members with absolute ease.</p> <h4>Features of the plugin include:</h4> <ul> <li>Front-end user profiles</li> <li>Front-end user registration</li> <li>Front-end user login</li> <li>Custom form fields</li> <li>Conditional logic for form fields</li> <li>Drag and drop form builder</li> <li>User account page</li> <li>Custom user roles</li> <li>Member directories</li> <li>User emails</li> <li>Content restriction</li> <li>Conditional nav menus</li> <li>Show author posts &amp; comments on user profiles</li> <li>Developer friendly with dozens of actions and filters</li> </ul> <p>Read about all of the plugin&#8217;s features at <a href="https://ultimatemember.com" rel="nofollow ugc">Ultimate Member</a></p> <h4>Paid Extensions</h4> <p>Ultimate Member has a range of extensions that allow you to extend the power of the plugin. You can purchase all of these extensions at a significant discount with one of our <a href="https://ultimatemember.com/pricing/" rel="nofollow ugc">paid plans</a> or you can purchase extensions individually.</p> <ul> <li><a href="https://ultimatemember.com/extensions/zapier/" rel="nofollow ugc">Zapier</a> &#8211; Allow to integrate the Zapier popular apps with Ultimate Member</li> <li><a href="https://ultimatemember.com/extensions/stripe/" rel="nofollow ugc">Stripe</a> &#8211; Sell paid memberships to access your website via Stripe subscriptions</li> <li><a href="https://ultimatemember.com/extensions/user-notes/" rel="nofollow ugc">User Notes</a> &#8211; Allow users to create public and private notes from their profile</li> <li><a href="https://ultimatemember.com/extensions/profile-tabs/" rel="nofollow ugc">Profile Tabs</a> &#8211; Allow to add the custom tabs to profiles</li> <li><a href="https://ultimatemember.com/extensions/user-locations/" rel="nofollow ugc">User Locations</a> &#8211; Allow to display users on a map on the member directory page and allow users to add their location via their profile</li> <li><a href="https://ultimatemember.com/extensions/unsplash/" rel="nofollow ugc">Unsplash</a> &#8211; Allow users to select a profile cover photo from <a href="https://unsplash.com/" rel="nofollow ugc">Unsplash</a> from their profile</li> <li><a href="https://ultimatemember.com/extensions/user-bookmarks/" rel="nofollow ugc">User Bookmarks</a> &#8211; Allow users to bookmark content from your website</li> <li><a href="https://ultimatemember.com/extensions/user-photos/" rel="nofollow ugc">User Photos</a> &#8211; Allow users to upload photos to their profile</li> <li><a href="https://ultimatemember.com/extensions/groups/" rel="nofollow ugc">Groups</a> &#8211; Allow users to create and join groups around shared topics, interests etc.</li> <li><a href="https://ultimatemember.com/extensions/private-content/" rel="nofollow ugc">Private Content</a> &#8211; Display private content to logged in users that only they can access</li> <li><a href="https://ultimatemember.com/extensions/user-tags/" rel="nofollow ugc">User Tags</a> &#8211; Lets you add a user tag system to your website</li> <li><a href="https://ultimatemember.com/extensions/social-activity/" rel="nofollow ugc">Social Activity</a> &#8211; Let users create public wall posts &amp; see the activity of other users</li> <li><a href="https://ultimatemember.com/extensions/woocommerce/" rel="nofollow ugc">WooCommerce</a> &#8211; Allow you to integrate WooCommerce with Ultimate Member</li> <li><a href="https://ultimatemember.com/extensions/private-messages/" rel="nofollow ugc">Private Messages</a> &#8211; Add a private messaging system to your site &amp; allow users to message each other</li> <li><a href="https://ultimatemember.com/extensions/followers/" rel="nofollow ugc">Followers</a> &#8211; Allow users to follow each other on your site and protect their profile information</li> <li><a href="https://ultimatemember.com/extensions/real-time-notifications/" rel="nofollow ugc">Real-time Notifications</a> &#8211; Add a notifications system to your site so users can receive real-time notifications</li> <li><a href="https://ultimatemember.com/extensions/social-login/" rel="nofollow ugc">Social Login</a> &#8211; Let users register &amp; login to your site via Facebook, Twitter, G+, LinkedIn, Instagram and Vkontakte (VK.com)</li> <li><a href="https://ultimatemember.com/extensions/bbpress/" rel="nofollow ugc">bbPress</a> &#8211; With the bbPress extension you can beautifully integrate Ultimate Member with bbPress</li> <li><a href="https://ultimatemember.com/extensions/mailchimp/" rel="nofollow ugc">MailChimp</a> &#8211; Allow users to subscribe to your MailChimp lists when they signup on your site and sync user meta to MailChimp</li> <li><a href="https://ultimatemember.com/extensions/user-reviews/" rel="nofollow ugc">User Reviews</a> &#8211; Allow users to rate &amp; review each other using a 5 star rate/review system</li> <li><a href="https://ultimatemember.com/extensions/verified-users/" rel="nofollow ugc">Verified Users</a> &#8211; Add a user verification system to your site so user accounts can be verified</li> <li><a href="https://ultimatemember.com/extensions/mycred/" rel="nofollow ugc">myCRED</a> &#8211; With the myCRED extension you can integrate Ultimate Member with the popular myCRED points management plugin</li> <li><a href="https://ultimatemember.com/extensions/notices/" rel="nofollow ugc">Notices</a> &#8211; Alert users to important information using conditional notices</li> <li><a href="https://ultimatemember.com/extensions/profile-completeness/" rel="nofollow ugc">Profile Completeness</a> &#8211; Encourage or force users to complete their profiles with the profile completeness extension</li> <li><a href="https://ultimatemember.com/extensions/friends/" rel="nofollow ugc">Friends</a> &#8211; Allows users to become friends by sending &amp; accepting/rejecting friend requests</li> </ul> <h4>Free Extensions</h4> <ul> <li><a href="https://ultimatemember.com/extensions/jobboardwp/" rel="nofollow ugc">JobsBoardWP</a> &#8211; This free extension integrates Ultimate Member with the job board plugin <a href="https://wordpress.org/plugins/jobboardwp" rel="ugc">JobBoardWP</a>.</li> <li><a href="https://ultimatemember.com/extensions/forumwp/" rel="nofollow ugc">ForumWP</a> &#8211; This free extension integrates Ultimate Member with the forum plugin <a href="https://forumwpplugin.com" rel="nofollow ugc">ForumWP</a>.</li> <li><a href="https://ultimatemember.com/extensions/terms-conditions/" rel="nofollow ugc">Terms &amp; Conditions</a> &#8211; Add a terms and condition checkbox to your registration forms &amp; require users to agree to your T&amp;Cs before registering on your site.</li> <li><a href="https://ultimatemember.com/extensions/google-recaptcha/" rel="nofollow ugc">Google reCAPTCHA</a> &#8211; Stop bots on your registration &amp; login forms with Google reCAPTCHA</li> <li><a href="https://ultimatemember.com/extensions/online-users/" rel="nofollow ugc">Online Users</a> &#8211; Display what users are online with this extension</li> </ul> <h4>Theme</h4> <p>Our official <a href="https://ultimatemember.com/theme/" rel="nofollow ugc">theme</a> is purpose built for websites that have logged in and out users. The <a href="https://ultimatemember.com/theme/" rel="nofollow ugc">theme</a> has deep integration with Ultimate Member plugin and the extensions, different header designs for logged-in/out users and works alongside the Beaver Builder and Elementor page builders.</p> <h4>Our other plugins</h4> <p>In addition to Ultimate Member, we also have two other plugins: <a href="https://forumwpplugin.com/" rel="nofollow ugc">ForumWP</a> and <a href="https://wordpress.org/plugins/jobboardwp" rel="ugc">JobBoardWP</a>.</p> <h4>ForumWP</h4> <p><a href="https://forumwpplugin.com/" rel="nofollow ugc">ForumWP</a> is a forum plugin which adds an online forum to your website, allowing users to create topics and write replies. Forums are a great way to build and grow an online community.</p> <h4>JobBoardWP</h4> <p><a href="https://wordpress.org/plugins/jobboardwp" rel="ugc">JobBoardWP</a> is a job board plugin which adds a modern job board to your website. Display job listings and allow employers to submit and manage jobs all from the front-end.</p> <h4>Development * Translations</h4> <p>If you&#8217;re a developer and would like to contribute to the source code of the plugin you can do so via our <a href="https://github.com/ultimatemember/ultimatemember" rel="nofollow ugc">GitHub Repository</a>.</p> <p>Want to add a new language to Ultimate Member? Great! You can contribute via <a href="https://translate.wordpress.org/projects/wp-plugins/ultimate-member" rel="nofollow ugc">translate.wordpress.org</a>.</p> <p>If you are a developer and you need to know the list of UM Hooks, make this via our <a href="https://docs.ultimatemember.com/article/1324-hooks-list" rel="nofollow ugc">Hooks Documentation</a> or <a href="https://ultimatemember.github.io/ultimatemember/hooks/" rel="nofollow ugc">Hooks Documentation v2</a>.</p> <p>If you are a developer and you need to know the structure of our code, make this via our <a href="https://ultimatemember.github.io/ultimatemember/phpdoc/" rel="nofollow ugc">Documentation API</a>.</p> <h4>Documentation &amp; Support</h4> <p>Got a problem or need help with Ultimate Member? Head over to our <a href="http://docs.ultimatemember.com/" rel="nofollow ugc">documentation</a> and perform a search of the knowledge base. If you can’t find a solution to your issue then you can create a topic on the <a href="https://wordpress.org/support/plugin/ultimate-member" rel="ugc">support forum</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
13.1M