ID:9174 - Exploit for Improper Authorization in Ultimate Member - User Profile & Membership Plugin - CVE-2023-3460
Published: July 5, 2023
Ultimate Member - User Profile & Membership Plugin
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected website.
The vulnerability exists due to improper authorization within the registration functionality. A remote non-authenticated attacker can register a rouge administrative account and compromise the web application.
Note, the vulnerability is being actively exploited in the wild.