CVE-2018-0586: Path Traversal
Published May 14, 2018
·Updated
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
Affected Software
1 affected component
ultimatemember User Profile \& Membership Wordpress<2.0.4
Event History
May 14, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0586?
CVE-2018-0586 is a directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress.
2
How does the directory traversal vulnerability in the shortcodes function of Ultimate Member plugin work?
The vulnerability allows remote authenticated attackers to read arbitrary files by exploiting unspecified vectors.
3
What is the severity of CVE-2018-0586?
The severity of CVE-2018-0586 is medium with a CVSS severity score of 4.3.
4
Which software is affected by CVE-2018-0586?
Ultimate Member plugin prior to version 2.0.4 for WordPress is affected by CVE-2018-0586.
5
How can I fix the directory traversal vulnerability in the Ultimate Member plugin?
To fix the vulnerability, update the Ultimate Member plugin to version 2.0.4 or later.