User Meta's vulnerability footprint is localized to a narrow set of user management and profile-building products with a modest disclosure history. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by User Meta over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23712HIGH Cross-Site Request Forgery (CSRF) vulnerability in User Meta Manager plugin <= 3.4.9 versions. | May 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-0779MEDIUM The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscr | Jun 8, 2022 | 6.5 | 24 | NO | NO |
CVE-2022-0376MEDIUM The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a | May 30, 2022 | 4.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by User Meta.
Media articles that mention a CVE ID that affects a product developed by User Meta — matched by CVE ID, not by vendor name.