AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-10271

MEDIUM · CVSS 4.3 EPSS 0.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-10271
Severity
MEDIUM
CVSS
4.3
EPSS
0.86%
WordPress

Original NVD Description

An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such a modification, one first needs to (for example) intercept an upload-picture request and modify the user_id parameter.