The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wp_usermeta table.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ultimatemember
Ultimatemember ultimate Member |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Ultimatemember
Ultimatemember ultimate Member |
Wed, 22 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 18 Jan 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wp_usermeta table. | |
Title | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-22T14:19:41.702Z
Reserved: 2025-01-07T22:50:30.349Z
Link: CVE-2025-0318

Updated: 2025-01-22T14:19:22.573Z

Status : Analyzed
Published: 2025-01-18T06:15:28.017
Modified: 2025-02-25T22:09:05.680
Link: CVE-2025-0318

No data.