Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, 3ccc5483-2dd9-4925-95dd-3faa5cfdb951
- CVE, Research URL
- Published on
- -
- Research Description
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.65 Ultimate Member < 1.3.65 - Local File Inclusion It was discovered that Ultimate Member is vulnerable to PHP File Inclusion. In order to exploit this issue an attacker must be able to place an arbitrary PHP file on the target system. Afterwards the attacker needs to lure an authenticated admin to visit a malicious page. Through CSRF the attacker could compromise WordPress, by executing the malicious PHP file.
- Affected versions
-
max 1.3.65.
- Status
-
vulnerable