Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.0.78 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.79 or latest
References
Related Vulnerabilities
WordPress Plugin Ad Manager by WD-Advanced Ad Manager Multiple Vulnerabilities (1.0.11)
WebLogic CVE-2024-21234 Vulnerability (CVE-2024-21234)
WordPress Plugin Photo Gallery, Images, Slider in Rbs Image Gallery Remote Code Execution (2.0.14)
Apache Traffic Server CVE-2024-35296 Vulnerability (CVE-2024-35296)