CVE-2026-18547 | Ultimate Member Plugin up to 2.12.1 on WordPress Textarea Profile Field pickadate.js html ID cross site scripting

SecurityVulns

A vulnerability identified as problematic has been detected in Ultimate Member Plugin up to 2.12.1 on WordPress. This impacts the function html of the file pickadate.js of the component Textarea Profile Field. Performing a manipulation of the argument ID results in cross site scripting.

This vulnerability is cataloged as CVE-2026-18547. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More