Product
The Ultimate Member WordPress plugin (<= 2.13.1) contains a stored XSS vulnerability in the form_id parameter, allowing unauthenticated attackers to execute arbitrary scripts in the administrator dashboard.