ZeroHour

CVE-2018-0588

CVSS 3.0
7.5 high
EPSS
3%p84
Published
()
Modified
Description

Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.

Vendors
ultimatemember
Products
user profile \& membership
Ecosystems
WordPress
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.