VulnerabilityModified
CVE-2018-0588
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
HIGH 7.5EPSS 2.60%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.60% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ultimatemember/user profile \& membership
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN28804532/index.htmlThird Party Advisory
- https://wordpress.org/plugins/ultimate-member/#developersRelease Notes
- https://wpvulndb.com/vulnerabilities/9608
- http://jvn.jp/en/jp/JVN28804532/index.htmlThird Party Advisory
- https://wordpress.org/plugins/ultimate-member/#developersRelease Notes
- https://wpvulndb.com/vulnerabilities/9608
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.