CVE-2020-36170: Ultimatemember Ultimate Member
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
Affected products
- Ultimatemember Ultimate Member: before 2.1.13 (fixed in 2.1.13)
Published 2021-01-06. Last modified 2026-06-17.