HomeSecurityUltimate Member: Critical vulnerability in WordPress plugin

Ultimate Member: Critical vulnerability in WordPress plugin

A critical vulnerability in the WordPress plugin Ultimate Member puts thousands of sites at risk .

Ultimate Member WordPress plugin vulnerability

Ultimate Member is a fairly popular plugin with over 200,000 active installations.

Security researcher Christiaan Swiers discovered the vulnerability, which is tracked as CVE-2024-1071 and carries a CVSS score of 9.8/10.

Last week, Wordfence published a report saying that the Ultimate Member plugin is “vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2.”

See also: Hackers exploit vulnerability in Bricks Builder WordPress Theme

According to the security team, unauthenticated attackers could exploit the vulnerability to add additional SQL queries to existing queries and extract sensitive data from the database.

It is worth noting that the issue only affects users who have clicked the “Enable custom table for usermeta” option in the WordPress plugin settings.

The plugin developers were notified of the vulnerability and released version 2.8.3 on February 19 to address it.

Users are urged to update Ultimate Member to the latest version as soon as possible, as attempts to exploit the vulnerability have already begun.

See also: Better Search Replace: Hackers target vulnerability in WordPress plugin

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Ultimate Member: Critical vulnerability in WordPress plugin
Ultimate Member: Critical vulnerability in WordPress plugin

Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies.

See also: Balada Injector Malware has infected 6,700 WordPress sites

Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers’ trust, preserving your company’s reputation, and staying on top of the competition.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS