First published: Mon May 14 2018(Updated: )
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0586 is a directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress.
The vulnerability allows remote authenticated attackers to read arbitrary files by exploiting unspecified vectors.
The severity of CVE-2018-0586 is medium with a CVSS severity score of 4.3.
Ultimate Member plugin prior to version 2.0.4 for WordPress is affected by CVE-2018-0586.
To fix the vulnerability, update the Ultimate Member plugin to version 2.0.4 or later.