plugin

User Meta Manager Vulnerabilities

5 known security issues reported for the User Meta Manager WordPress plugin. Most recent disclosed Jan 19, 2023.

3 high 2 medium

Running User Meta Manager on your site? Check whether your installed version is affected.

Scan your site free

User Meta Manager <= 3.4.9 - Reflected Cross-Site Scripting

medium

The User Meta Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...

CVSS:
6.3
Affected:
up to 3.4.9
Fix:
No patched version reported
Disclosed:
Jan 19, 2023

CVE-2023-22718 on NVD →

User Meta Manager <= 3.4.9 - Cross Site Request Forgery

high

The User Meta Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.9. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site adm...

CVSS:
8.8
Affected:
up to 3.4.8
Fix:
No patched version reported
Disclosed:
Jan 10, 2023

CVE-2023-23712 on NVD →

User Meta Manager Plugin < 3.4.7 - Privilege Escalation

high

The User Meta Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the umm_update_user_meta() function in versions up to, and including, 3.4.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to escalate their account to...

CVSS:
8.8
Affected:
up to 3.4.7
Fixed in:
3.4.7
Disclosed:
Feb 2, 2016

User Meta Manager < 3.4.8 - Missing Authorization to Sensitive Information Disclosure

medium

The User Meta Manager for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.4.7 via several functions called through unprotected AJAX actions. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to extract sensitive data including all dat...

CVSS:
6.5
Affected:
up to 3.4.8
Fixed in:
3.4.8
Disclosed:
Feb 1, 2016

User Meta Manager < 3.4.7 - Authenticated Blind SQL Injection

high

The User Meta Manager plugin for WordPress is vulnerable to blind SQL Injection via the ‘umm_user’ parameter in versions before 3.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append add...

CVSS:
8.8
Affected:
up to 3.4.7
Fixed in:
3.4.7
Disclosed:
Feb 4, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database