Medium severity4.8NVD Advisory· Published Apr 23, 2018· Updated Jun 17, 2026
CVE-2018-10234
CVE-2018-10234
Description
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.0.11
- Range: <2.0.11
Patches
Vulnerability mechanics
References
2- github.com/RiieCco/write-ups/tree/master/CVE-2018-10234nvdExploitThird Party Advisory
- wordpress.org/plugins/ultimate-member/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.