"Ultimate Member Plugin Flaw Exposes 100,000 WordPress Sites to Attacks"
"Ultimate Member Plugin Flaw Exposes 100,000 WordPress Sites to Attacks"
According to security researchers at Defiant, a high-severity vulnerability in the Ultimate Member plugin can be exploited to inject malicious scripts into WordPress sites. Tracked as CVE-2024-2123, the vulnerability is described as a stored cross-site scripting (XSS) issue via several parameters, allowing attackers to inject web scripts into a site’s pages to be executed whenever those pages are loaded. The researchers noted that the flaw exists because of insufficient input sanitization and output escaping.