User Meta Manager <= 3.4.9 - Reflected Cross-Site Scripting
medium
The User Meta Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...
- CVSS:
- 6.3
- Affected:
- up to 3.4.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 19, 2023
CVE-2023-22718 on NVD →
User Meta Manager <= 3.4.9 - Cross Site Request Forgery
high
The User Meta Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.9. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site adm...
- CVSS:
- 8.8
- Affected:
- up to 3.4.8
- Fix:
- No patched version reported
- Disclosed:
- Jan 10, 2023
CVE-2023-23712 on NVD →
User Meta Manager Plugin < 3.4.7 - Privilege Escalation
high
The User Meta Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the umm_update_user_meta() function in versions up to, and including, 3.4.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to escalate their account to...
- CVSS:
- 8.8
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.7
- Disclosed:
- Feb 2, 2016
User Meta Manager < 3.4.8 - Missing Authorization to Sensitive Information Disclosure
medium
The User Meta Manager for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.4.7 via several functions called through unprotected AJAX actions. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to extract sensitive data including all dat...
- CVSS:
- 6.5
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Feb 1, 2016
User Meta Manager < 3.4.7 - Authenticated Blind SQL Injection
high
The User Meta Manager plugin for WordPress is vulnerable to blind SQL Injection via the ‘umm_user’ parameter in versions before 3.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append add...
- CVSS:
- 8.8
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.7
- Disclosed:
- Feb 4, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database