Improper Authentication in Ultimate Membership Pro - #VU25010
Published: February 6, 2020
Vulnerability identifier: #VU25010
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insufficient authentication. A remote attacker can bypass authentication process and execute arbitrary code on the target system or gain access to sensitive information.
Affected software
Ultimate Membership Pro
Remediation
Install updates from vendor's website.
Ultimate Membership Pro - update to 8.6.1