Sploitus

CVE-2018-17866

No indexed exploits for CVE-2018-17866 yet

Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.

Affected products
Ultimate Member
Ultimatemember Ultimate Member
< 2.0.28
Fix
Available
CVSS 3.0
6.1 MEDIUM
EPSS
1.6% (75th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2018-10-09
CVE-2018-17866 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-17866 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-17866 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.