ID:9174 - Exploit for Improper Authorization in Ultimate Member - User Profile & Membership Plugin - CVE-2023-3460

 
Main Vulnerability Database Exploits ID:9174 - Exploit for Improper Authorization in Ultimate Member - User Profile & Membership Plugin - CVE-2023-3460

ID:9174 - Exploit for Improper Authorization in Ultimate Member - User Profile & Membership Plugin - CVE-2023-3460

Published: July 5, 2023


Vulnerability identifier: #VU77841
Vulnerability risk: Critical
CVE-ID: CVE-2023-3460
CWE-ID: CWE-285
Exploitation vector: Remote access
Vulnerable software:
Ultimate Member - User Profile & Membership Plugin

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected website.

The vulnerability exists due to improper authorization within the registration functionality. A remote non-authenticated attacker can register a rouge administrative account and compromise the web application.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.