cleantalk
Vulnerabilities and Security Researches

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, 3ccc5483-2dd9-4925-95dd-3faa5cfdb951

Published on
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.65 Ultimate Member &lt; 1.3.65 - Local File Inclusion It was discovered that Ultimate Member is vulnerable to PHP File Inclusion. In order to exploit this issue an attacker must be able to place an arbitrary PHP file on the target system. Afterwards the attacker needs to lure an authenticated admin to visit a malicious page. Through CSRF the attacker could compromise WordPress, by executing the malicious PHP file.
Affected versions
max 1.3.65.
Status
vulnerable