CyberRota Analysis
AI-GeneratedThe Ultimate Member WordPress plugin prior to version 2.13.1 is vulnerable due to improper escaping of user-supplied profile names, which can lead to stored cross-site scripting (XSS) attacks. This flaw allows unauthenticated attackers to inject malicious JavaScript that executes when any visitor, including administrators, views the compromised profile. WordPress site administrators and users of the Ultimate Member plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.