ZeroHour

CVE-2018-0587

CVSS 3.0
4.3 medium
EPSS
1%p63
Published
()
Modified
Description

Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.

Vendors
ultimatemember
Products
user profile \& membership
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.