vulnerability

WordPress Plugin: ultimate-member: CVE-2020-36170: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Dec 9, 2020
Added
May 15, 2025
Modified
May 15, 2025

Description

The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden nameequal to"timestamp" fields in forms.

Solution

ultimate-member-plugin-cve-2020-36170
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.