CVE-2022-1209
Dashboard / Vulnerabilities / CVE-2022-1209
CVE-2022-1209
Summary: Ultimate Member <= 2.3.1 - Arbitrary Redirect
Details: The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
References: https://github.com/H4de5-7/vulnerabilities/blob/main/Ultimate%20Member%20%3C%3D%202.3.1%20-%20Open%20Redirect.md, https://www.wordfence.com/threat-intel/vulnerabilities/id/d638120b-5396-408b-8273-d003ff9dd01d?source=cve, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1209.json, https://nvd.nist.gov/vuln/detail/CVE-2022-1209, https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1209, https://github.com/ultimatemember/ultimatemember/issues/989, https://github.com/ultimatemember/ultimatemember/pull/990
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
