CVE-2022-1209
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
- Affected products
- Ultimate Member
- Ultimatemember Ultimate Member
- ≤ 2.3.1
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-601
- NVD status
- Modified
- Published
- 2022-05-10
CVE-2022-1209 at NVD
No indexed exploits for CVE-2022-1209 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-1209 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.