ZeroHour

CVE-2018-0586

CVSS 3.0
4.3 medium
EPSS
2%p74
Published
()
Modified
Description

Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.

Vendors
ultimatemember
Products
user profile \& membership
Ecosystems
WordPress
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.