Sploitus

CVE-2022-3383

No indexed exploits for CVE-2022-3383 yet

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative capabilities, to execute code on the server.

Affected products
Ultimate Member
Ultimatemember Ultimate Member
≤ 2.5.0
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
2.8% (85th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2022-11-29
CVE-2022-3383 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-3383 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-3383 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.