Aller au contenu

Fiche vulnérabilité

CVE-2022-3384 : faille élevée ultimatemember Ultimate Member – User… (CVSS 7.2)

Description

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user supplied parameters are not passed through the function. This makes it possible for authenticated attackers, with administrative privileges, to execute code on the server.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 nov. 2022
Dernière mise à jour
8 avr. 2026

Produits concernés

  • ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

Références

Rechercher une autre vulnérabilité dans la base CVE