Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40135 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6. |
Wed, 29 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6. | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. |
| Title | WordPress Indeed Ultimate Membership Pro plugin <= 12.6 - Unauthenticated PHP Object Injection vulnerability | WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated PHP Object Injection vulnerability |
| References | ||
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 06 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpindeed
Wpindeed ultimate Membership Pro |
|
| CPEs | cpe:2.3:a:wpindeed:ultimate_membership_pro:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpindeed
Wpindeed ultimate Membership Pro |
Tue, 03 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Azzaroco
Azzaroco ultimate Membership Pro |
|
| CPEs | cpe:2.3:a:azzaroco:ultimate_membership_pro:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azzaroco
Azzaroco ultimate Membership Pro |
|
| Metrics |
ssvc
|
Mon, 19 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6. | |
| Title | WordPress Indeed Ultimate Membership Pro plugin <= 12.6 - Unauthenticated PHP Object Injection vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-29T09:51:52.936Z
Reserved: 2024-08-09T09:20:24.968Z
Link: CVE-2024-43242
Updated: 2024-09-03T15:00:04.963Z
Status : Modified
Published: 2024-08-19T18:15:10.463
Modified: 2026-04-29T10:16:33.130
Link: CVE-2024-43242
No data.
OpenCVE Enrichment
No data.
EUVD