cleantalk
Vulnerabilities and Security Researches

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, b725e2ed5313af59fc42a3d4aef17fea598573d6

Published on
Aug 08, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 Ultimate Member <= 2.0.21 - Arbitrary File Upload The Arbitrary File Upload plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.0.21. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected versions
max 2.0.22.
Status
vulnerable