Improper Authorization in Ultimate Member - User Profile & Membership Plugin - CVE-2023-3460
Published: June 30, 2023 / Updated: July 27, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected website.
The vulnerability exists due to improper authorization within the registration functionality. A remote non-authenticated attacker can register a rouge administrative account and compromise the web application.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2023-3460
Links to Public Exploits and PoC-codes
- Exploit #9207 - CVE-2023-3460 (Exploit for the vulnerability of Ultimate Member Plugin.) (July 27, 2023)
- Exploit #9183 - CVE-2023-3460 (Exploit and scanner for CVE-2023-3460) (July 15, 2023)
- Exploit #9174 - CVE-2023-3460 (Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7) (July 5, 2023)