Sploitus

CVE-2022-3384

No indexed exploits for CVE-2022-3384 yet

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user supplied parameters are not passed through the function. This makes it possible for authenticated attackers, with administrative privileges, to execute code on the server.

Affected products
Ultimate Member
Ultimatemember Ultimate Member
≤ 2.5.0
CVSS 3.1
7.2 HIGH
EPSS
2.7% (85th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2022-11-29
CVE-2022-3384 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-3384 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-3384 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.