First published: Mon May 14 2018(Updated: )
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0587 is an unrestricted file upload vulnerability in the Ultimate Member plugin for WordPress.
The severity of CVE-2018-0587 is medium with a score of 4.3.
CVE-2018-0587 allows remote authenticated users to upload arbitrary image files via unspecified vectors.
The Ultimate Member plugin prior to version 2.0.4 for WordPress is affected by CVE-2018-0587.
To fix CVE-2018-0587, update the Ultimate Member plugin to version 2.0.4 or later.