cleantalk
Vulnerabilities and Security Researches

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, CVE-2018-0588

CVE, Research URL

CVE-2018-0588

Published on
May 14, 2018
Research Description
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
Affected versions
max 2.0.40.
Status
vulnerable