#VU77841 Improper Authorization in Ultimate Member - User Profile & Membership Plugin - CVE-2023-3460
Published: June 30, 2023 / Updated: July 27, 2023
Ultimate Member - User Profile & Membership Plugin
Ultimate Member
Description
The vulnerability allows a remote attacker to compromise the affected website.
The vulnerability exists due to improper authorization within the registration functionality. A remote non-authenticated attacker can register a rouge administrative account and compromise the web application.
Note, the vulnerability is being actively exploited in the wild.