CVE-2025-15064 | ultimatemember Ultimate Member Plugin up to 2.11.1 on WordPress Setting user description cross site scripting (EUVD-2025-209217)
A vulnerability was found in ultimatemember Ultimate Member Plugin up to 2.11.1 on WordPress. It has been rated as problematic. Affected is an unknown function of the component Setting Handler. Performing a manipulation of the argument user description results in cross site scripting.
This vulnerability is cataloged as CVE-2025-15064. It is possible to initiate the attack remotely. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.