CyberRota Analysis
AI-GeneratedThe Ultimate Member WordPress plugin prior to version 2.12.0 is vulnerable due to inadequate sanitization of custom textarea profile fields, enabling authenticated users with Subscriber-level access or higher to inject malicious JavaScript. This flaw can lead to cross-site scripting (XSS) attacks, potentially compromising user sessions and exposing sensitive information when profiles are viewed. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate the risk.
Original NVD Description
The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.