Input validation vulnerability in Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 1.3.65

The Ultimate Member plugin for WordPress is vulnerable to a security issue known as Local File Inclusion. This affects versions 1.3.64 and lower of the plugin. An unauthenticated attacker can include and execute arbitrary files on the server by exploiting the “page” parameter. This can allow them to bypass security controls, steal sensitive data, or execute code by uploading and including images and other “safe” file types.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.