Ultimate Member Ultimate Member是Ultimate Member团队的一款用户会员管理插件。 Ultimate Member 2.12.0之前版本存在跨站脚本漏洞,该漏洞源于未正确清理和转义自定义文本区域个人资料字段的值,可能导致认证用户(订阅者级别及以上)存储JavaScript脚本,当任何用户(包括管理员)查看受影响个人资料时执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Ultimate Member | < 2.12.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Ultimate Member | 0 ~ 2.12.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6382 | Multiple elFinder Plugins - Authenticated OS Command Injection | |
| CVE-2026-11855 | Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version | |
| CVE-2026-11962 | FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations | |
| CVE-2026-12083 | Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via r | |
| CVE-2026-10830 | AllCoach < 1.0.2 - Unauthenticated Account Takeover | |
| CVE-2024-6228 | WANotifier < 2.6 - Subscriber+ LFI |
No comments yet