Code Injection in Ultimate Member - User Profile & Membership Plugin - CVE-2022-3383
Published: October 31, 2022
Ultimate Member - User Profile & Membership Plugin
Ultimate Member
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.