Ultimate Member
cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:wordpress:*:*
- <= 2.9.1
A time-based SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.9.1. The vulnerability arises from inadequate escaping of user-supplied data in the search parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.
Exploitation of this vulnerability could allow an attacker to manipulate SQL queries, potentially leading to unauthorized data access or disclosure of sensitive information from the WordPress database.
To reproduce this vulnerability, send a request to a member directory that uses the Ultimate Member plugin version 2.9.1 or earlier. Include a crafted search parameter that exploits the SQL injection vulnerability by appending additional SQL commands. The injection can be verified by extracting data from the database, such as user information or other sensitive details.
Users are advised to update the Ultimate Member WordPress plugin to version 2.9.2 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.