A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-04-03T04:12:07
Updated: 2024-08-04T22:32:01.019Z
Reserved: 2019-03-31T00:00:00
Link: CVE-2019-10673
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-04-03T05:29:00.210
Modified: 2024-11-21T04:19:43.800
Link: CVE-2019-10673
Redhat
No data.