Ultimate Member
cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:wordpress:*:*
- <= 2.9.1
A vulnerability allowing information exposure has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.9.1. The issue arises from the plugin's error handling, which inadvertently reveals sensitive information through various error messages. This flaw enables unauthenticated attackers to extract data from the WordPress usermeta database table.
Exploitation of this vulnerability allows for unauthorized access to sensitive user metadata, which could include personal information and other private details stored in the usermeta table.
Users can address this vulnerability by updating the Ultimate Member WordPress plugin to version 2.9.2 or a later patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.