First published: Mon May 14 2018(Updated: )
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-0588.
The severity of CVE-2018-0588 is high.
The affected software is Ultimate Member plugin prior to version 2.0.4 for WordPress.
The vulnerability can be exploited by remote attackers to read arbitrary files.
Yes, the fix for CVE-2018-0588 is to update Ultimate Member plugin to version 2.0.4 or higher.